CVE-2026-76639: Unitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridge and Path Traversal

Published Aug 27, 2026
·
Updated

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chatgo knowledge upload API. Attackers can publish DDS control messages to restart the bashrunner service, plant a malicious payload in its script execution directory via path traversal, and trigger execution of that payload as uid 0 through the bashrunner shell subprocess.

Affected Software

1 affected component
Unitree G1 EDU<=1.5.2

Event History

Aug 27, 2026
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Unitree G1 EDU devices running firmware through 1.5.2 are affected when a network-adjacent attacker can reach the WebRTC-to-DDS bridge on TCP port 9991.

2

Does exploitation require authentication or prior access?

No. The described attack is unauthenticated and requires no privileges or user interaction; the attacker needs network-adjacent access to the affected service.

3

What level of access can an attacker gain?

By chaining the DDS bridge, exposed static AES-128 key, and knowledge-upload path traversal, an attacker can execute arbitrary commands as root (uid 0).

4

What can be done if firmware cannot be updated immediately?

Restrict network access to TCP port 9991 so untrusted or network-adjacent systems cannot reach the WebRTC-to-DDS bridge.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203