- Sources: primary, discussion
- Summary: The write-up assigns CVE-2026-76639 to a chat_go path traversal and bashrunner whitelist chain that gave a standalone root shell over Ethernet or the robot's access point, and CVE-2026-76640 to a five-bug Bluetooth chain whose documented steps include a GATT characteristic registered with bare write permission, a Unitree cloud endpoint that returned any robot's AES-128 key to any free account without an ownership check, a heredoc injection in WiFi configuration, and a 1050-byte BSS overflow. The stated affected versions cover only the G1 builds the researcher directly tested, reproduced on four G1 units, with firmware V1.5.1.1 and V1.5.2 named in the timeline, and related Go2, B2, and R1 builds are not treated as proven vulnerable. The timeline records Unitree implementing an account-to-robot binding ownership check before returning the key between 2026-07-01 and 2026-08-06, and states Unitree now has patches, some internal at the time of posting, for the large majority if not all of the vulnerabilities.
- Why it matters: The chain's fleet-wide reach, including robot-to-robot spread within Bluetooth range, rested on a cloud endpoint serving per-device keys with no ownership check, which the timeline records Unitree gating during disclosure, and the author asks that the write-up be read as a point-in-time account of the platform during the research and disclosure period rather than a description of its current security posture.
- Follow-up: Track publication of CVE-2026-76639 and CVE-2026-76640, and whether Unitree states which firmware builds carry the fixes.
send feedback on this story