PT-2026-82732 · Unitree · G1 Edu

·

CVE-2026-76639

·

Published

2026-08-27

·

Updated

2026-09-01

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Unitree G1 EDU firmware versions prior to 1.5.3
Description An unauthenticated remote code execution flaw allows network-adjacent attackers to execute arbitrary commands as root. This is achieved by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat go knowledge upload API. Attackers can publish DDS control messages to restart the bashrunner service, use path traversal to place a malicious payload in the script execution directory, and trigger the execution of that payload as uid 0 through the bashrunner shell subprocess.
Recommendations Update Unitree G1 EDU firmware to a version newer than 1.5.2. Restrict access to TCP port 9991 to minimize the risk of exploitation. Avoid using the chat go knowledge upload API until the issue is resolved.

Exploit

Fix

RCE

Path traversal

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76639

Affected Products

G1 Edu