Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Bluetooth Vulnerability Exposes Unitree G1 Robots

Bluetooth Vulnerability Exposes Unitree G1 Robots

Posted on August 29, 2026 By CWS

Researchers have uncovered a severe vulnerability in Unitree G1 humanoid robots, enabling attackers within Bluetooth range to gain root-level access. This critical flaw affects the robot’s locomotion computer, which governs its movement, cameras, and other essential functions.

The UniBLEed Security Flaw

The security issue, known as UniBLEed, involves multiple stages of exploitation. It leverages Bluetooth Low Energy technology, the Unitree cloud API, and the robot’s Wi-Fi provisioning system. Hackers can use this flaw to execute root-level code on the robot’s control environment, impacting major hardware functions.

Assigned CVE-2026-76639 and CVE-2026-76640, the attack has been recreated on four Unitree G1 robots. The exploit begins with a Bluetooth service that allows writing without pairing, sending requests to a specific GATT characteristic to receive an encrypted package from the robot.

Exploiting Encryption Vulnerabilities

This exploit takes advantage of Unitree’s decrypt-and-bind endpoint, turning it into a decryption oracle for nearby robots. Attackers can retrieve the AES-128 encryption key, initially protected by RSA encryption, from this endpoint. The cloud API, devicebindExtData, would decrypt this data without verifying if the user account owned the targeted robot.

Hackers could use a free Unitree account to collect the necessary information from a nearby G1 robot, submit it to the cloud API, and obtain the robot-specific AES key. This oversight is an authorization failure, as the API fails to confirm the account-to-robot ownership link.

Wi-Fi and Bluetooth Exploitation Risks

After obtaining the AES key, attackers can finalize the Bluetooth handshake and send Wi-Fi setup commands. Researchers noted that by crafting an overlong password, attackers could manipulate the script handling Wi-Fi configurations, forcing the robot to connect to a malicious hotspot.

Further exploitation involves a flaw in the G1 Bluetooth server. A buffer overflow vulnerability allows attackers to corrupt memory by sending a large payload, potentially altering server processes and executing commands as root.

Another root code execution path exploits the ChatGo AI service and BashRunner service, using a path traversal issue to execute files with root privileges. This poses significant risks, as these Linux services control critical robot functions.

Preventive Measures and Future Outlook

In response, Unitree implemented ownership-binding checks for their cloud decryption endpoints in July 2026. Researchers advise robot owners to update to the latest firmware and apps, avoid exposing robots to unfamiliar Bluetooth devices, and isolate robot networks from sensitive systems.

Preventing such vulnerabilities is crucial to maintaining the security of robotic systems. By staying informed and applying necessary updates, users can safeguard their devices against potential threats.

Cyber Security News Tags:Bluetooth Low Energy, Bluetooth vulnerability, cloud API, CVE-2026-76639, CVE-2026-76640, Cybersecurity, Encryption, Hacking, Linux security, robot security, Robotics, root access, Unitree G1, Wi-Fi security

Post navigation

Previous Post: ServiceNow Updates Address Critical Security Vulnerabilities
Next Post: Malvertising Threats Evolve with Complex Infrastructure Tactics

Related Posts

Critical Bug in WordPress Plugin Risks 400,000 Sites Critical Bug in WordPress Plugin Risks 400,000 Sites Cyber Security News
Cloudflare Outage Traced to Emergency React2Shell Patch Deployment Cloudflare Outage Traced to Emergency React2Shell Patch Deployment Cyber Security News
Chinese Cybersecurity Firm Data Breach Exposes State-Sponsored Hackers Cyber Weapons and Target List Chinese Cybersecurity Firm Data Breach Exposes State-Sponsored Hackers Cyber Weapons and Target List Cyber Security News
North Korean Hackers Infiltrated 136 U.S. Companies to Generate .2 Million in Revenue North Korean Hackers Infiltrated 136 U.S. Companies to Generate $2.2 Million in Revenue Cyber Security News
Google Warns Multiple Hacker Groups Are Exploiting React2Shell to Spread Malware Google Warns Multiple Hacker Groups Are Exploiting React2Shell to Spread Malware Cyber Security News
Beware of Weaponized ScreenConnect App That Delivers AsyncRAT and PowerShell RAT Beware of Weaponized ScreenConnect App That Delivers AsyncRAT and PowerShell RAT Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management
  • Browser Extension Risks AI Assistant Security
  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management
  • Browser Extension Risks AI Assistant Security
  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark