The record
Written from the 1 report below. Nothing here is unsourced.
- A security researcher has disclosed two flaws that could let an attacker run commands with full root control on Unitree's G1 EDU humanoid robot, one through a network-adjacent route and another starting from nearby Bluetooth Low Energy access.
- The issues are tracked as CVE-2026-76639 and CVE-2026-76640, and no fixed firmware release has been confirmed, leaving owners without a clear update target.
- Unitree did patch a related cloud account check in July 2026 that closed one attack path, but the Bluetooth-based problems are separate and were demonstrated on August 27, 2026.
What to watch next
- Whether Unitree responds with confirmed fixed firmware versions and the affected product scope, as The Hacker News has requested
- Whether the two vulnerabilities are found to affect other Unitree robot models beyond the G1 EDU
- Which exact firmware versions, such as V1.5.1.1, are verified as affected
Coverage1
1 report
English national1
All filed from India
Named China · Unitree · Unitree G1 EDU · Olivier Laflamme
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
