Key Points
- 1.Unitree robots have critical security flaws allowing remote code execution.
- 2.Hard-coded Bluetooth keys across units pose a severe threat.
- 3.Injection of terminal commands via Wi-Fi credentials can be executed as root.
- 4.The issue impacts multiple models including G1, H1, B2, and R1.
Summary
Critical Security Vulnerabilities
Unitree robots, including models G1, H1, B2, and R1, face significant security risks due to flaws that enable remote code execution. This vulnerability arises from hard-coded Bluetooth keys and allows unauthorized control of the robots by anyone with close-range access.
Risks of Hard-Coded Keys
All Unitree robots use identical hard-coded AS keys, which compromise security. These keys allow for unintended access, enabling malicious users to execute arbitrary commands on the robot's main board.
Command Injection Capability
The findings reveal that by manipulating Wi-Fi credentials, it's possible to inject commands, effectively granting root access to the device. This represents a major oversight in the robot's firmware design and poses a threat to users.
Demonstration of Vulnerabilities
The video includes a live demonstration showcasing how these vulnerabilities can be exploited. It aims to provide concrete evidence of the risks and reassess the previous claims that were dismissed by Unitree.
Worth watching for
This video is for individuals interested in robotics security, ethical hacking, and owners or potential buyers of Unitree robots.