{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/g1-edu/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-76639"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["G1 EDU"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Unitree"],"content_html":"\u003cp\u003eUnitree G1 EDU firmware versions up to 1.5.2 are affected by a severe unauthenticated remote code execution vulnerability (CVE-2026-76639). The vulnerability stems from an insecure WebRTC-to-DDS bridge listening on TCP port 9991. By leveraging this bridge alongside a static AES-128 key discovered in world-readable storage and a path traversal flaw in the chat_go knowledge upload API, network-adjacent attackers can execute arbitrary code with root (uid 0) privileges. The vulnerability permits an attacker to manipulate the bashrunner service, allowing them to plant malicious payloads in execution directories and subsequently trigger their execution. This chain provides complete control over the robot platform, necessitating immediate firmware updates or the restriction of network access to the management interfaces.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies the target G1 EDU device reachable on TCP port 9991.\u003c/li\u003e\n\u003cli\u003eThe attacker connects to the unauthenticated WebRTC-to-DDS bridge on port 9991.\u003c/li\u003e\n\u003cli\u003eThe attacker retrieves the static AES-128 key from the device's world-readable local storage to decrypt or spoof control messages.\u003c/li\u003e\n\u003cli\u003eThe attacker publishes crafted DDS control messages designed to restart the bashrunner service.\u003c/li\u003e\n\u003cli\u003eThe attacker exploits a path traversal vulnerability in the chat_go knowledge upload API to upload a malicious binary or script.\u003c/li\u003e\n\u003cli\u003eThe payload is placed into the bashrunner script execution directory through the directory traversal.\u003c/li\u003e\n\u003cli\u003eThe attacker triggers the bashrunner service, which executes the injected payload.\u003c/li\u003e\n\u003cli\u003eThe injected code executes as uid 0, granting the attacker full root access to the device.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full unauthenticated root access to the Unitree G1 EDU robot. This allows for total control over the robot's physical functions, potential data exfiltration, and the ability to persist within the environment. Given the nature of these robotic platforms, this impact extends to physical safety risks and total compromise of the robotic control system.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the latest firmware updates provided by Unitree for G1 EDU units immediately to resolve the path traversal and authentication gaps.\u003c/li\u003e\n\u003cli\u003eRestrict network access to TCP port 9991; this port should not be exposed to untrusted networks or the public internet.\u003c/li\u003e\n\u003cli\u003eAudit filesystem permissions on affected devices to ensure cryptographic keys and sensitive configuration files are not world-readable.\u003c/li\u003e\n\u003cli\u003eImplement network-level segmentation to isolate robotic hardware management interfaces from general-purpose network traffic.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T21:10:15Z","date_published":"2026-08-27T21:10:15Z","id":"https://feed.craftedsignal.io/briefs/2026-08-unitree-g1-rce/","summary":"Unitree G1 EDU firmware through 1.5.2 is susceptible to unauthenticated remote code execution allowing root-level command injection via a chained exploit targeting the WebRTC-to-DDS bridge, hardcoded credentials, and path traversal in the knowledge upload API.","title":"Unauthenticated RCE in Unitree G1 EDU Firmware","url":"https://feed.craftedsignal.io/briefs/2026-08-unitree-g1-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - G1 EDU","version":"https://jsonfeed.org/version/1.1"}