Wormable RCE Vulnerabilities Found in Unitree Robots

matthew_d_green · x · 2026-08-22

Security researchers disclosed two Remote Code Execution vulnerabilities (CVE-2026-27509 & CVE-2026-27510) in Unitree robots. Attackers can gain root access via DDS protocol or mobile app database tampering. The exploit is wormable, meaning one compromised robot could infect nearby vulnerable units, potentially allowing attackers to hijack entire fleets.

Original post →

More from Embodied

Embodied channel →