Product
Unitree G1 EDU firmware through 1.5.2 is susceptible to unauthenticated remote code execution allowing root-level command injection via a chained exploit targeting the WebRTC-to-DDS bridge, hardcoded credentials, and path traversal in the knowledge upload API.