Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

Two root remote code execution flaws found in Unitree G1 EDU robot

Two root remote code execution vulnerabilities (CVE-2026-76639, CVSS 8.8, and CVE-2026-76640, CVSS 7.5) affect the Unitree G1 EDU robot, with one flaw exploiting a network-adjacent path via chat_go and bashrunner and the other leveraging BLE proximity to trigger a buffer overflow during Wi-Fi provisioning. As of the August 27, 2026 disclosure, a confirmed fixed firmware release for the G1 EDU has not been publicly verified, leaving no clear remediation target or workaround available.
Read Full Article →

IoT Two root remote code execution flaws found in Unitree G1 EDU robot August 28, 2026 Share By SC Staff (Adobe Stock) Based on information from The Hacker News, security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU robot. One of these chains utilizes Bluetooth Low Energy (BLE) to achieve root access on the robot's Locomotion PC. The vulnerabilities, tracked as CVE-2026-76639 and CVE-2026-76640, present distinct attack vectors. CVE-2026-76639 involves a network-adjacent path through chat_go and bashrunner, leading to root code execution. The second flaw, CVE-2026-76640, begins with BLE proximity, allowing an attacker to initiate a bootstrap interaction without prior pairing. This BLE path can exploit a buffer overflow during Wi-Fi provisioning operations to achieve root execution. A previously identified authorization gap in Unitree's cloud service, which allowed key material recovery for unauthorized accounts, has reportedly been patched. However, as of the disclosure on August 27, 2026, a confirmed fixed firmware release for the G1 EDU has not been publicly verified, leaving owners without a clear remediation target. The broader applicability of these flaws to other Unitree robot models remains unconfirmed. Source: The Hacker News SC Staff Related IoT New malware targets Android car head units for ad fraud and botnet creation SC Staff August 21, 2026 Kaspersky discovered the threat in June 2026, noting that the malware spreads through the built-in updaters of the head unit firmware. IoT Operation CameraSwarm compromises over 14,500 Dahua devices SC Staff August 20, 2026 The campaign, primarily impacting devices in Ukraine and Russia, leveraged CVE-2021-33044 and CVE-2021-33045, two authentication-bypass flaws rated 9.8 CVSS by the NVD. IoT Malicious SIM cards can take over cellular-connected devices SC Staff August 12, 2026 Researchers from the University of Birmingham and Fuzzware discovered that nine out of 26 tested devices, including several Quectel cellular modules and specific OPPO and ASUS phone models, were susceptible to use of the RUN AT command. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article