Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-76640
Unitree G1 EDU 1.5.2 BLE GATT RCE via WiFi Provisioning Stack
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
A H N N N H H H 7.7 .0034 25.8 —
AFFECTED
Product Versions Fixed
G1 EDU unspecified —
TIMELINE
Aug 19 Reserved by VulnCheck
Aug 27 Published (CNA: VulnCheck)
Aug 28 EXPLOIT PUBLISHED — CVE-2026-76640 (Unitree Robotics G1 EDU). Public exploit reference added.
Description
Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentials by exploiting an unquoted heredoc variable in the WiFi provisioning script and a buffer overflow in the SSID chunk accumulator. Attackers can send crafted BLE writes to overflow a fixed BSS buffer across BLE connections, corrupting an adjacent mainloop function pointer dispatch entry that is subsequently invoked by the cleanup path passing attacker-controlled data to system() as uid 0.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 19, 2026 | Reserved | Reserved by VulnCheck |
| August 27, 2026 | Published | Published (CNA: VulnCheck) |
| August 28, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-76640 (Unitree Robotics G1 EDU). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Unitree Robotics | G1 EDU | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-76640 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.