Critical Active Exploitation Alert: Unitree G1 EDU Humanoid Robot Vulnerabilities (CVE-2026-76639, CVE-2026-76640) Enable Root RCE via Bluetooth and Chatbot Flaws

Critical Active Exploitation Alert: Unitree G1 EDU Humanoid Robot Vulnerabilities (CVE-2026-76639, CVE-2026-76640) Enable Root RCE via Bluetooth and Chatbot Flaws

Executive Summary

Two critical vulnerabilities, CVE-2026-76639 and CVE-2026-76640, have been identified in the Unitree G1 EDU Humanoid Robot. These flaws enable unauthenticated attackers to achieve root remote code execution (RCE), with one exploit chain accessible via Bluetooth Low Energy (BLE) and wormable, allowing compromise of any G1 robot within BLE range. The second exploit leverages a path traversal in the robot’s AI chatbot and can be triggered over the local network or via BLE after initial compromise. Successful exploitation grants full root control of the robot, including movement, sensor access, and sensitive cloud credentials. Security researchers have demonstrated exploitation in the wild, and the vulnerabilities are considered critical.

Technical Information

The vulnerabilities affect the Unitree G1 EDU Humanoid Robot running firmware versions up to and including v1.5.2. The first vulnerability, CVE-2026-76639, is a path traversal flaw in the chat_go AI chatbot service. The chatbot’s knowledge upload API fails to sanitize file paths, allowing an attacker to write arbitrary files to any location, including the bashrunner script whitelist directory. By sending a specially crafted DDS message with a uid containing path traversal sequences (such as ../../../../../unitree/module/bashrunner/content_acquisition/pwn), an attacker can write a malicious shell script to the bashrunner’s directory. The attacker can then restart the bashrunner service via another DDS message, causing it to pick up the new script, and finally instruct bashrunner to execute the script, achieving root code execution. This exploit chain can be triggered over the local network (WebRTC/DDS) or via BLE after initial compromise. The attack is mapped to MITRE ATT&CK techniques T1059 (Command and Scripting Interpreter) and T1105 (Ingress Tool Transfer).

The second vulnerability, CVE-2026-76640, is a BLE-based wormable root RCE chain in the custom btgatt-server BLE GATT server. The BLE characteristic 0xFFE2 allows unauthenticated writes, and the BLE bootstrap opcode (0xF2) returns the robot’s AES-128 key in an RSA-encrypted blob. Prior to patching, any Unitree cloud account could decrypt this blob, as there was no ownership check. WiFi provisioning via BLE allows attacker-controlled SSID and password, which are injected unsafely into a heredoc in a shell script, enabling configuration injection. Critically, a 1050-byte buffer overflow in the WiFi SSID handler allows overwriting function pointers in the event loop, leading to arbitrary code execution as root. The exploit chain involves connecting to the robot over BLE, requesting the bootstrap blob, using the Unitree cloud API to decrypt the AES key, completing the BLE handshake, sending WiFi credentials with a malicious payload, and finally sending a 1050-byte SSID payload to overflow the buffer and trigger execution of a root shell command. This attack is mapped to MITRE ATT&CK techniques T1210 (Exploitation of Remote Services) and T1068 (Exploitation for Privilege Escalation).

Both vulnerabilities have been demonstrated by a security researcher, with proof-of-concept scripts available on boschko.ca. The BLE exploit is particularly dangerous due to its wormability: a compromised G1 can attack other G1s within BLE range, potentially leading to rapid propagation in environments with multiple robots.

Exploitation in the Wild

Exploitation of both vulnerabilities has been demonstrated by independent security researchers, notably one researcher. There is no evidence of exploitation by advanced persistent threat (APT) groups or criminal organizations as of this report. The vulnerabilities are not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and thus there is no CISA-confirmed active exploitation. However, the public availability of proof-of-concept code and the critical nature of the flaws significantly elevate the risk of real-world attacks.

APT Groups using this vulnerability

At the time of writing, there are no public reports or intelligence indicating that any APT groups or criminal organizations are exploiting CVE-2026-76639 or CVE-2026-76640. All observed exploitation has been conducted by independent security researchers for responsible disclosure and demonstration purposes.

Affected Product Versions

The affected product is the Unitree G1 EDU Humanoid Robot, specifically all firmware versions up to and including v1.5.2. While the researcher has confirmed exploitation only on the G1 EDU, it is possible that other Unitree robots, such as the Go2, B2, and R1, may share vulnerable code. Organizations using any Unitree robots should consult the vendor for clarification and apply mitigations as appropriate.

Workaround and Mitigation

Unitree has responded by patching the cloud API to require account-to-robot binding for AES key decryption, closing the cloud API abuse vector. Firmware updates addressing the BLE and chatbot vulnerabilities are in progress. Organizations should immediately update their Unitree G1 EDU robots to the latest firmware as soon as it becomes available. If BLE functionality is not required, it should be disabled to reduce the attack surface. Administrators should monitor for unauthorized scripts in /unitree/module/bashrunner/content_acquisition/, unexpected WiFi SSID changes, and unusual BLE activity. Outbound connections from the robot to unknown IPs or reverse shells should be investigated promptly. For the latest firmware and security advisories, consult the Unitree Security Portal.

Indicators of Compromise

The following table contains real, published indicators of compromise (IOCs) extracted from public technical sources. These indicators are point-in-time and should be validated before enforcement in your environment.

Type

Indicator

Reported (date)

Source

 

Domain

boschko[.]ca

2026-08-27

https://boschko.ca/g1-ble-rce/

Domain

cybersecuritynews[.]com

2026-08-27

https://cybersecuritynews.com/unitree-g1-robots-over-bluetooth/

Domain

www[.]reddit[.]com

2026-08-27

https://www.reddit.com/r/SecOpsDaily/comments/1w0rl4e/two_unitree_g1_edu_humanoid_robot_flaws_enable/

URL

hxxps://boschko[.]ca/g1-ble-rce/

2026-08-27

https://boschko.ca/g1-ble-rce/

URL

hxxps://cybersecuritynews[.]com/unitree-g1-robots-over-bluetooth/

2026-08-27

https://cybersecuritynews.com/unitree-g1-robots-over-bluetooth/

URL

hxxps://www[.]reddit[.]com/r/SecOpsDaily/comments/1w0rl4e/two_unitree_g1_edu_humanoid_robot_flaws_enable/

2026-08-27

https://www.reddit.com/r/SecOpsDaily/comments/1w0rl4e/two_unitree_g1_edu_humanoid_robot_flaws_enable/

References

Rescana is here for you

Rescana empowers organizations to manage third-party risk and supply chain security with our advanced TPRM platform, providing continuous monitoring, automated risk assessment, and actionable intelligence.

Our team is dedicated to supporting your cybersecurity needs and helping you stay ahead of emerging threats.

We are happy to answer questions at info@rescana.com.