60
55
55
60
Vulnerability Spotlight: Information Disclosure Vulnerability in Lexmark Perceptive Document Filters
60
42
42
30
30
30
30
55
30
30
30
42
30
30
30
55
30
42
55
30
30
42
55
55
30
60
55
55
Hack One Robot, Reach the Next: Unitree G1 Security Flaws
Researcher chained two Unitree G1 flaws (CVE-2026-76639, CVE-2026-76640) to gain unauthenticated root access, with compromised robots able to infect others via Bluetooth.
Security researcher Olivier Laflamme chained a path-traversal file-write flaw (CVE-2026-76639) in the G1 chatbot service and a Bluetooth server buffer overflow (CVE-2026-76640) to achieve unauthenticated root access remotely. The chain abuses Unitree's cloud API as a decryption oracle for the AES-128 key that unlocks BLE and WebRTC channels, and a compromised robot can propagate the attack to nearby G1 units. Unitree patched the cloud ownership-check flaw, paid a $5,000 bounty, and firmware fixes for BLE pairing and the buffer overflow remain harder to deliver.
58
55
30
55
55
55
55
55