Humanoid Robot Vulnerability Tracker
Every publicly disclosed vulnerability and security incident affecting humanoid robots, plus related legged and consumer robots, in one place. Each entry links to the original advisory or research. We update this tracker as new disclosures appear.
Last updated: October 4, 2026. Know of a disclosure we missed? Email info@humanoidthreats.com.
Humanoid robots
| Disclosed | Robot | ID | What it allows | Severity | Fix status |
|---|---|---|---|---|---|
| Aug 27, 2026 | Unitree G1 EDU | CVE-2026-76639 | Root code execution over the network through the robot's AI chatbot service. Researcher showed one hacked G1 could reach a second G1. | Root access | No fixed firmware publicly confirmed as of late Aug 2026 |
| Aug 27, 2026 | Unitree G1 EDU | CVE-2026-76640 | Root code execution over Bluetooth Low Energy from nearby, with no pairing. | Root access | No fixed firmware publicly confirmed as of late Aug 2026 |
| Sep 26, 2025 | Unitree G1, H1 (also Go2, B2) | CVE-2025-35027 ("UniPwn") | Command injection while configuring Wi-Fi over BLE, leading to root command execution. Affected: G1 and H1 firmware 1.4.4 and earlier. | 7.3 High | Affected versions listed; update to later firmware |
| Sep 26, 2025 | Unitree G1, H1 (also Go2, B2) | CVE-2025-60250 | Hardcoded encryption key and IV used to decrypt Bluetooth packet data. | 4.7 Medium | Affects versions through Sep 20, 2025 |
| Sep 2025 | Unitree G1 | No CVE (research) | Security assessment reported hardcoded keys and telemetry sent to remote servers every few minutes without notifying the user. The vendor has said it does not collect private data without authorization. | Privacy / data exposure | Disputed by vendor |
Quadrupeds, cobots and consumer robots
| Disclosed | Robot | ID | What it allows | Severity | Fix status |
|---|---|---|---|---|---|
| May 8, 2026 | Universal Robots cobots (PolyScope 5) | CVE-2026-8153 | Unauthenticated OS command injection in the Dashboard Server interface, giving full control of the robot's operating system. | 9.8 Critical | Fixed in PolyScope 5.25.1 |
| Mar 10, 2026 | Hookii Neomow mower, Hypershell X exoskeleton, HOBOT S7 Pro window cleaner | Multiple (research) | 38 vulnerabilities found in about 7 hours by an AI-assisted research team, 30 rated Critical or High, including root access and control of connected devices through shared credentials. | 30 Critical/High | See vendor advisories |
| Sep 26, 2025 | Unitree Go2, B2 quadrupeds | CVE-2025-35027, CVE-2025-60250 | Same BLE Wi-Fi setup flaws as the G1 and H1 entries above. Affected: Go2 and B2 firmware 1.1.8 and earlier. | 7.3 High / 4.7 Medium | Update to later firmware |
| Mar 28, 2025 | Unitree Go1 quadruped | CVE-2025-2894 | Undocumented backdoor allowing remote control through the CloudSail service for anyone with the right API key. | 6.6 Medium | Go1 is discontinued; isolate or retire units |
What the pattern shows
Most humanoid and legged-robot flaws so far share three entry points: Bluetooth and Wi-Fi setup, cloud and remote-control services, and AI assistant interfaces that reach the operating system. Several give full root access. Fix status is often unclear, so buyers should ask vendors directly which firmware version addresses each CVE. For the background, read Can humanoid robots be hacked? and our Unitree G1 CVE explainer. To protect a fleet, use the Humanoid Robot Security Checklist and find vendors in the security directory.
Sources
- The Hacker News: Two Unitree G1 EDU humanoid robot flaws
- GitHub Advisory: CVE-2025-35027
- OpenCVE: CVE-2025-60250
- Mayoral-Vilches et al., Unitree G1 security assessment (arXiv)
- OpenCVE: CVE-2026-8153
- Cybersecurity AI: Hacking Consumer Robots in the AI Era (arXiv)
- OpenCVE: CVE-2025-2894
Get new robot vulnerabilities in your inbox every Thursday: subscribe to The Humanoid Threats Brief.