CVE-2026-76639: Unitree Robotics g1 Edu
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API. Attackers can publish DDS control messages to restart the bashrunner service, plant a malicious payload in its script execution directory via path traversal, and trigger execution of that payload as uid 0 through the bashrunner shell subprocess.
Affected products
- Unitree Robotics g1 Edu: up to and including 1.5.2
Published 2026-08-27. Last modified 2026-09-08.