SECURITY·중요도 9·2026. 08. 28.·The Hacker News

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

── KO ──────────────────

Unitree G1 EDU 로봇의 RCE 취약점이 발견되었습니다.

보안 연구원 Olivier Laflamme가 Unitree G1 EDU 로봇의 원격 코드 실행(RCE) 취약점 두 가지를 공개했습니다. 이중 하나는 Bluetooth Low Energy(BLE)를 통해 루트 권한에 접근할 수 있는 경로입니다. 두 취약점은 CVE-2026-76639와 CVE-2026-76640으로 추적되고 있으며, 첫 번째는 chat_go와 bashrunner를 이용한 네트워크 인접 경로에 관련되어 있습니다.


── EN ──────────────────

Two RCE vulnerabilities found in Unitree G1 EDU robot.

Security researcher Olivier Laflamme disclosed two remote code execution (RCE) vulnerabilities in the Unitree G1 EDU robot. One vulnerability allows root access through a Bluetooth Low Energy (BLE) path. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner.

원문 보기 →목록으로