PT-2026-82733 · Unitree · G1 Edu
CVSS v3.1
7.5
High
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Unitree G1 EDU firmware versions prior to 1.5.3
Description
Multiple chained issues exist in the BLE GATT server and WiFi provisioning stack. Unauthenticated proximate attackers can achieve root code execution without pairing or credentials. This is possible by exploiting a buffer overflow in the SSID chunk accumulator and an unquoted heredoc variable in the WiFi provisioning script. Attackers can send crafted BLE writes to overflow a fixed BSS buffer across BLE connections, which corrupts an adjacent mainloop function pointer dispatch entry. This entry is later invoked by the cleanup path, passing attacker-controlled data to the
system() function as uid 0.Recommendations
Update Unitree G1 EDU firmware to a version newer than 1.5.2.
Exploit
Fix
RCE
Memory Corruption
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
G1 Edu