宇树科技(Unitree)G1 EDU 型机器人的固件(版本 1.5.2 及之前版本)存在一个未认证远程代码执行漏洞,允许处于网络邻接位置的攻击者以 root 身份执行任意命令。该漏洞由三个安全缺陷串联而成: 1. 未认证的 WebRTC 到 DDS 桥接服务:在 TCP 9991 端口上运行,无需身份验证即可访问。 2. 静态 AES-128 密钥:密钥以全局可读(world-readable)的权限存储,易被泄露。 3. 聊天_go 知识上传 API 中的路径遍历缺陷:允许通过路径遍历机制写入文件到预期之外的位
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unitree Robotics | G1 EDU | 0 ~ 1.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet