Skip to main content
Back to Newswire
Security Robotics

Researchers disclose two root-code-execution paths in Unitree G1 EDU

Researchers disclose two root-code-execution paths in Unitree G1 EDU Image: Primary
Security researcher Olivier Laflamme disclosed two root remote-code-execution chains affecting Unitree's G1 EDU humanoid robot, including one that begins through Bluetooth Low Energy and reaches the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640. Unitree patched a cloud account-to-robot ownership check in July, which breaks the demonstrated cloud-assisted route, but no exact fixed firmware release has been verified for either vulnerability.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire