S1 · 08/27
2026 ·
Unitree
| Company | Unitree |
| Category | humanoid |
| Type | cyber |
| Date | 08/27 2026 |
| Time of day | not documented |
| Location | no physical site (recall / fleet-wide / aggregate record) |
| Severity | S1 (near-miss / disclosed vulnerability) |
| Scale | fleet-wide (G1 EDU model) |
| Confidence | high |
| Verification | Cited source on file; not independently re-verified |
| Source | The Hacker News |
A security researcher disclosed two chained remote-code-execution vulnerabilities in the Unitree G1 EDU humanoid -- one network-adjacent via chat_go/bashrunner, one via Bluetooth proximity plus a Wi-Fi provisioning buffer overflow -- together allowing unauthenticated root access to any G1 within Bluetooth range, with no confirmed fixed firmware publicly verified at disclosure.