Impact
Unitree Robotics G1 EDU firmware versions 1.5.2 and earlier contain a chained vulnerability that enables an unauthenticated network-adjacent attacker to achieve remote code execution with root privileges. The flaw is composed of an exposed WebRTC‑to‑DDS bridge on TCP port 9991, a world‑readable static AES‑128 key, and a path‑traversal vulnerability in the chat_go knowledge upload API. By sending DDS control messages, an attacker can restart the bashrunner service, place a malicious script in its execution directory via path traversal, and have that script run as uid 0 through the bashrunner shell subprocess. This results in full system compromise, allowing arbitrary command execution, data exfiltration, and persistence.
Affected Systems
Unitree Robotics G1 EDU firmware versions 1.5.2 and earlier are affected.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. EPSS information is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local network attacker exploiting the unauthenticated WebRTC‑to‑DDS bridge on TCP port 9991, with no user interaction required. Once the bridge is accessed, the attacker can chain the static key misuse and path traversal to gain root access.
OpenCVE Enrichment