PT-2026-82733 · Unitree · G1 Edu

·

CVE-2026-76640

·

Published

2026-08-27

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Unitree G1 EDU firmware versions prior to 1.5.3
Description Multiple chained issues exist in the BLE GATT server and WiFi provisioning stack. Unauthenticated proximate attackers can achieve root code execution without pairing or credentials. This is possible by exploiting a buffer overflow in the SSID chunk accumulator and an unquoted heredoc variable in the WiFi provisioning script. Attackers can send crafted BLE writes to overflow a fixed BSS buffer across BLE connections, which corrupts an adjacent mainloop function pointer dispatch entry. This entry is later invoked by the cleanup path, passing attacker-controlled data to the system() function as uid 0.
Recommendations Update Unitree G1 EDU firmware to a version newer than 1.5.2.

Exploit

Fix

RCE

Memory Corruption

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76640

Affected Products

G1 Edu