CVE-CVE-2026-76639
Severity
HIGH
CVSS Score
8.8
Description
Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API. Attackers can publish DDS control messages to restart the bashrunner service, plant a malicious payload in it...
PoCs for CVE-CVE-2026-76639
UniBLEed
RCE
0
OlivierLaflamme
2026-08-24