PT-2026-82732 · Unitree · G1 Edu
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Unitree G1 EDU firmware versions prior to 1.5.3
Description
An unauthenticated remote code execution flaw allows network-adjacent attackers to execute arbitrary commands as root. This is achieved by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the
chat go knowledge upload API. Attackers can publish DDS control messages to restart the bashrunner service, use path traversal to place a malicious payload in the script execution directory, and trigger the execution of that payload as uid 0 through the bashrunner shell subprocess.Recommendations
Update Unitree G1 EDU firmware to a version newer than 1.5.2.
Restrict access to TCP port 9991 to minimize the risk of exploitation.
Avoid using the
chat go knowledge upload API until the issue is resolved.Exploit
Fix
RCE
Path traversal
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
G1 Edu