Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
Security researcher Olivier Laflamme disclosed two root RCE chains affecting Unitree G1 EDU robots, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC.
Intelligence analysis by Qwen 2.5 (3B)

Security researcher discovers two root RCE vulnerabilities in Unitree G1 EDU humanoid robots, one of which starts over BLE.
Two robots could be tricked into letting someone take control of them. The bad guys could use this to do bad things with the robots, like steal information or cause damage.
Analysis
{"subheading":"Unitree G1 EDU Robot Flaws","paragraph_1":"Security researcher Olivier Laflamme has disclosed two root remote code execution (RCE) chains affecting the Unitree G1 EDU humanoid robot. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640.","paragraph_2":"CVE-2026-76639 involves a network-adjacent path through chat_go and bashrunner, while CVE-2026-76640 begins from BLE proximity. Laflamme said Unitree patched the cloud account-to-robot ownership check in July 2026.","paragraph_3":"Laflamme documented a buffer overflow in the Wi-Fi provisioning code, which produced root execution on the Locomotion PC. He limited his propagation test to two G1 robots in one room."}
Key points
- Two root RCE vulnerabilities disclosed in Unitree G1 EDU robots
- One flaw starts over BLE, allowing for root execution on the Locomotion PC
- Unitree patched the cloud account-to-robot ownership check in July 2026
Unitree may release a fix for the vulnerabilities, which could help protect the robots from being taken over.
If the vulnerabilities are not fixed, attackers could use them to control the robots, which could be dangerous.



