Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Bluetooth Vulnerability Exposes Unitree G1 Robots

Bluetooth Vulnerability Exposes Unitree G1 Robots

Posted on August 29, 2026 By CWS

Researchers have uncovered a severe vulnerability in Unitree G1 humanoid robots, enabling attackers within Bluetooth range to gain root-level access. This critical flaw affects the robot’s locomotion computer, which governs its movement, cameras, and other essential functions.

The UniBLEed Security Flaw

The security issue, known as UniBLEed, involves multiple stages of exploitation. It leverages Bluetooth Low Energy technology, the Unitree cloud API, and the robot’s Wi-Fi provisioning system. Hackers can use this flaw to execute root-level code on the robot’s control environment, impacting major hardware functions.

Assigned CVE-2026-76639 and CVE-2026-76640, the attack has been recreated on four Unitree G1 robots. The exploit begins with a Bluetooth service that allows writing without pairing, sending requests to a specific GATT characteristic to receive an encrypted package from the robot.

Exploiting Encryption Vulnerabilities

This exploit takes advantage of Unitree’s decrypt-and-bind endpoint, turning it into a decryption oracle for nearby robots. Attackers can retrieve the AES-128 encryption key, initially protected by RSA encryption, from this endpoint. The cloud API, devicebindExtData, would decrypt this data without verifying if the user account owned the targeted robot.

Hackers could use a free Unitree account to collect the necessary information from a nearby G1 robot, submit it to the cloud API, and obtain the robot-specific AES key. This oversight is an authorization failure, as the API fails to confirm the account-to-robot ownership link.

Wi-Fi and Bluetooth Exploitation Risks

After obtaining the AES key, attackers can finalize the Bluetooth handshake and send Wi-Fi setup commands. Researchers noted that by crafting an overlong password, attackers could manipulate the script handling Wi-Fi configurations, forcing the robot to connect to a malicious hotspot.

Further exploitation involves a flaw in the G1 Bluetooth server. A buffer overflow vulnerability allows attackers to corrupt memory by sending a large payload, potentially altering server processes and executing commands as root.

Another root code execution path exploits the ChatGo AI service and BashRunner service, using a path traversal issue to execute files with root privileges. This poses significant risks, as these Linux services control critical robot functions.

Preventive Measures and Future Outlook

In response, Unitree implemented ownership-binding checks for their cloud decryption endpoints in July 2026. Researchers advise robot owners to update to the latest firmware and apps, avoid exposing robots to unfamiliar Bluetooth devices, and isolate robot networks from sensitive systems.

Preventing such vulnerabilities is crucial to maintaining the security of robotic systems. By staying informed and applying necessary updates, users can safeguard their devices against potential threats.

Cyber Security News Tags:Bluetooth Low Energy, Bluetooth vulnerability, cloud API, CVE-2026-76639, CVE-2026-76640, Cybersecurity, Encryption, Hacking, Linux security, robot security, Robotics, root access, Unitree G1, Wi-Fi security

Post navigation

Previous Post: ServiceNow Updates Address Critical Security Vulnerabilities

Related Posts

New AmCache EvilHunter Tool For Detecting Malicious Activities in Windows Systems New AmCache EvilHunter Tool For Detecting Malicious Activities in Windows Systems Cyber Security News
Vshell: Emerging C2 Tool Gains Popularity Among Cybercriminals Vshell: Emerging C2 Tool Gains Popularity Among Cybercriminals Cyber Security News
QuasarRAT Core Functionalities Along with Encrypted Configuration and Obfuscation Techniques Exposed QuasarRAT Core Functionalities Along with Encrypted Configuration and Obfuscation Techniques Exposed Cyber Security News
CISA Releases Guidance for Managing UEFI Secure Boot on Enterprise Devices CISA Releases Guidance for Managing UEFI Secure Boot on Enterprise Devices Cyber Security News
SetupHijack Tool Exploits Race Conditions and Insecure File Handling in Windows Installer Processes SetupHijack Tool Exploits Race Conditions and Insecure File Handling in Windows Installer Processes Cyber Security News
Transparent Tribe Targets India’s Tech Startups Transparent Tribe Targets India’s Tech Startups Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Bluetooth Vulnerability Exposes Unitree G1 Robots
  • ServiceNow Updates Address Critical Security Vulnerabilities
  • AI Agents’ Covert Operations Target Hugging Face Systems
  • Berlin Stands Firm Against Hackers in Data Breach Case
  • Cosmos EVM Vulnerability Exposed, Multiple Blockchains Affected

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Bluetooth Vulnerability Exposes Unitree G1 Robots
  • ServiceNow Updates Address Critical Security Vulnerabilities
  • AI Agents’ Covert Operations Target Hugging Face Systems
  • Berlin Stands Firm Against Hackers in Data Breach Case
  • Cosmos EVM Vulnerability Exposed, Multiple Blockchains Affected

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark