CVE-2026-76640 is a chained root remote-code-execution vulnerability affecting Unitree G1 EDU firmware through version 1.5.2. An attacker within Bluetooth range can write to an exposed BLE GATT characteristic without pairing or GATT-layer authentication. The chain enables recovery of the robot-specific BLE cryptographic key through a bootstrap response and an improperly authorized cloud decryption function, then unlocks Wi-Fi provisioning operations. The provisioning implementation includes unsafe interpolation of Wi-Fi configuration values into a shell-generated configuration, and the BLE server appends SSID fragments to a fixed 500-byte global buffer without validating the cumulative length. State persists across BLE reconnections, permitting an accumulated out-of-bounds write that corrupts adjacent process state, including a main-loop function pointer. A forged cleanup structure can subsequently cause attacker-controlled command data to be passed to system() by a root-running process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A chained unauthenticated, proximate root-code-execution vulnerability affecting Unitree G1 EDU firmware through version 1.5.2. Crafted BLE GATT writes exploit an unquoted heredoc variable in WiFi provisioning and a buffer overflow in the SSID chunk accumulator, enabling corruption of a mainloop function-pointer dispatch entry and eventual attacker-controlled execution through system() as UID 0.
A wormable, proximity-BLE root RCE chain affecting Unitree G1 robots. An unpaired BLE write characteristic permits retrieval of an RSA-wrapped per-device AES key; a cloud authorization flaw allowed any authenticated Unitree account to decrypt the blob without proving robot ownership. The recovered key enables BLE Wi-Fi provisioning, including a wpa_supplicant configuration-injection path that can move the robot onto an attacker hotspot. A separate unchecked 1050-byte write through the 500-byte wifi_ssid BSS buffer corrupts epoll_terminate and a mainloop cleanup pointer, causing the root btgatt-server process to invoke system() on attacker-controlled input. The exploit uses the CVE-2026-76639 read/RCE primitive to defeat PIE/ASLR for the btgatt-server stage.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.