Wormable RCE Vulnerabilities Found in Unitree Robots
matthew_d_green · x · 2026-08-22
Security researchers disclosed two Remote Code Execution vulnerabilities (CVE-2026-27509 & CVE-2026-27510) in Unitree robots. Attackers can gain root access via DDS protocol or mobile app database tampering. The exploit is wormable, meaning one compromised robot could infect nearby vulnerable units, potentially allowing attackers to hijack entire fleets.
More from Embodied
- Humanoid Robot Crashes at Beijing 'Robot Olympics' Sprint — steveplunkett · 2026-08-22
- Deep Dive: How World Models Unlock Physical AI and Robotics — risingodegua · 2026-08-22
- RoboRobots Cuts Robot Deployment Costs to $10/hr, Seeks Fleet Partners — ai · 2026-08-22
- Humanoid robots walk in air and form bands at World Humanoid Robot Games rehearsal — CyberRobooo · 2026-08-22
- Robotics gatekeeping: No motor/driver build, no entry — wavefnx · 2026-08-22
- DIY Coil Winder: Building Custom Actuators from Scratch — IanPritchard · 2026-08-22