宇树科技(Unitree)G1 EDU 机器人固件(版本至 1.5.2)中的 BLE GATT 服务和 WiFi 配网(provisioning)协议栈存在多个可串联利用的漏洞。未认证的近距离攻击者无需配对或凭据,可通过利用 WiFi 配网脚本中的未加引号的 here-doc 变量漏洞,以及 SSID 块累加器中的缓冲区溢出漏洞,实现以 root 权限执行代码。 攻击者可构造特定的 BLE 写入操作,在固定的 BSS 缓冲区上通过多个 BLE 连接累积写入以触发溢出,从而破坏相邻的主循环函数指针分派表项;该表项随后
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unitree Robotics | G1 EDU | 0 ~ 1.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet