A Unitree robot exploit spreads to nearby robots over Bluetooth
One hacked Unitree robot can now infect the robots standing next to it, and it does not need Wi-Fi to do so.
What the exploit does
Security researchers published UniPwn, an exploit chain for Unitree’s Go2 and B2 quadrupeds and its G1 and H1 humanoids. The two flaws are tracked as CVE-2026-27509 and CVE-2026-27510.
An attacker within Bluetooth range can get root on the robot without any password. The payload survives reboots. Once a unit is compromised, it can reach other Unitree robots nearby over the same Bluetooth link and compromise them too, so a single infected robot can become an entry point into a whole fleet.
Why a self-spreading root exploit matters here
Unitree is one of the most widely sold robot makers in the world. Its quadrupeds run in research labs, police departments and factories, often in groups. A root exploit that propagates between units turns every deployed robot into a potential foothold, and every neighbor into the next target.
The practical problem is patch delivery. Unlike a cloud service, each affected robot is a physical device in the field, and a fix has to reach each one. Until that happens, fleets that sit within Bluetooth range of each other carry the highest exposure.
What to watch
The open questions are how quickly Unitree ships firmware that closes the Bluetooth path, and how many operators apply it. Robots on corporate or lab networks are increasingly treated like any other networked endpoint, and this exploit chain is an argument for giving them the same security review as a server.
Sources
ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.