Unitree G1 Robot Vulnerabilities Enable Unauthenticated Remote Code Execution

Unitree G1 Robot Vulnerabilities Enable Unauthenticated Remote Code Execution

First seen 28 Aug 2026, 13:22 UTC GbhackersThehackernews 51.9

Article Content

Browse articles
ThreatCluster

Security researcher Boschko disclosed two vulnerabilities in the Unitree G1 humanoid robot, allowing unauthenticated remote code execution (RCE) via Bluetooth Low Energy (BLE). The vulnerabilities, part of the research named UniBLEed, can compromise the robot's Locomotion PC, which is critical for its operations. The affected systems include the Unitree G1 humanoid robot, specifically the EDU version. The attack method allows nearby devices to exploit these flaws without authentication. No specific CVEs were mentioned in the articles. The vulnerabilities pose a significant risk as they could lead to unauthorized control of the robot. Current status indicates that the vulnerabilities have been disclosed but not yet confirmed as actively exploited. Users of the affected robots are advised to monitor for updates and potential patches from Unitree.

Key Points: • Two critical vulnerabilities in Unitree G1 humanoid robots allow unauthenticated RCE. • Exploitation can occur via Bluetooth Low Energy without user authentication. • The vulnerabilities affect the robot's Locomotion PC, essential for its functions.

Timeline

2026-08-28
Vulnerabilities disclosed
Researcher Boschko revealed two vulnerabilities in the Unitree G1 humanoid robot, enabling unauthenticated RCE via BLE.
Gbhackers
2026-08-28
Second article published
The Hacker News reported on the same vulnerabilities, emphasizing the risk of RCE in the Unitree G1 EDU version.
Thehackernews