Unitree Robotics G1 Edu vulnerabilities
2 known vulnerabilities affecting unitree_robotics/g1_edu.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2026-76639P2HIGHCVSS 8.8≤ 1.5.22026-08-27
CVE-2026-76639 [HIGH] CWE-22 CVE-2026-76639: Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerabilit
Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw
nvd
CVE-2026-76640P3HIGHCVSS 7.5≤ 1.5.22026-08-27
CVE-2026-76640 [HIGH] CWE-306 CVE-2026-76640: Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT serv
Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentials by exploiting an unquoted heredoc variable in the WiFi provisioning script and a buffer overflow in the SSID chun
nvd