Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76639— Unitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridge and Path Traversal

Quick assessment

Affected
Unitree Robotics G1 EDU
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

宇树科技(Unitree)G1 EDU 型机器人的固件(版本 1.5.2 及之前版本)存在一个未认证远程代码执行漏洞,允许处于网络邻接位置的攻击者以 root 身份执行任意命令。该漏洞由三个安全缺陷串联而成: 1. 未认证的 WebRTC 到 DDS 桥接服务:在 TCP 9991 端口上运行,无需身份验证即可访问。 2. 静态 AES-128 密钥:密钥以全局可读(world-readable)的权限存储,易被泄露。 3. 聊天_go 知识上传 API 中的路径遍历缺陷:允许通过路径遍历机制写入文件到预期之外的位

CVSS 8.8 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76639

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridge and Path Traversal
Source: CVE Program / CVE List V5
Vulnerability Description
Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API. Attackers can publish DDS control messages to restart the bashrunner service, plant a malicious payload in its script execution directory via path traversal, and trigger execution of that payload as uid 0 through the bashrunner shell subprocess.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unitree Robotics G1 EDU 0 ~ 1.5.2 -

II. Public POCs for CVE-2026-76639

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-76639

登录查看更多情报信息。

Vendor Advisories for CVE-2026-76639 (1)

Exploits & Public PoCs for CVE-2026-76639 (1)

Other References for CVE-2026-76639 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-76639

No comments yet


Leave a comment