Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

A pair of critical vulnerabilities in the Unitree G1 EDU humanoid robot have been uncovered, allowing hackers to gain root access and execute malicious code on the device. The flaws, which affect both the Bluetooth and wired connections of the robot, pose a significant threat to educational institutions that rely on these robots for teaching artificial intelligence and robotics.

The Unitree G1 EDU is a popular robotic platform designed specifically for educational purposes. It’s equipped with advanced sensors, AI-powered algorithms, and a range of programming languages that make it an attractive tool for students learning about robotics and computer science. However, the robot’s reliance on Bluetooth connectivity creates a vulnerability that can be exploited by attackers.

According to security researchers, one of the vulnerabilities allows hackers to gain access to the robot via its Bluetooth connection. This enables malicious actors to execute arbitrary code on the device, effectively granting them root-level access. The second flaw affects the robot’s wired connection and can be used to exploit a cross-domain privilege escalation vulnerability. In both cases, the attacks are facilitated by the robot’s default configuration settings.

The severity of these vulnerabilities is compounded by their potential impact on educational institutions that rely heavily on the Unitree G1 EDU for teaching AI and robotics. An attacker with root access could potentially disrupt the learning environment, compromise student data, or even use the robot as a springboard to launch further attacks on the institution’s network.

The security flaws in question are likely to be attributed to poor configuration settings that allow for cross-domain privilege escalation. In technical terms, this refers to an attack path where an attacker gains elevated privileges by exploiting vulnerabilities in multiple domains or systems within a network. The Unitree G1 EDU robot appears to have an inherent susceptibility to such attacks due to its design and implementation.

It’s worth noting that these flaws are not unique to the Unitree G1 EDU, but rather highlight the broader issue of IoT device security. With the increasing adoption of connected devices in various industries, the potential for vulnerabilities like these will only continue to grow unless manufacturers prioritize robust security measures in their designs.

As a result of this discovery, educational institutions and organizations that use the Unitree G1 EDU robot should take immediate action to address the vulnerabilities. This includes updating the device’s firmware to the latest version, disabling Bluetooth connectivity when not in use, and implementing robust network segmentation and monitoring practices to detect potential attacks.


Source: The Hacker News — 2026-08-28