One Robot Vulnerability Got a Patch. The Other Got an IPO.
Universal Robots patched a critical, unauthenticated remote-code-execution flaw in its PolyScope 5 controller within a normal coordinated-disclosure cycle. A wormable Bluetooth exploit affecting Unitree's G1, H1, Go2, and B2 robots has gone unpatched for over a year, surviving the company's IPO and a return appearance at IFA Berlin. The gap between the two responses tracks who each company sells to, not how dangerous the machine is.

On September 20, 2025, two independent researchers published a complete working exploit for every Unitree G1, H1, Go2, and B2 robot then in service. The chain needed no password: a single AES encryption key and initialization vector, hardcoded and identical across the entire product line, unlocked a Bluetooth handshake that checked for nothing more than the literal string "unitree." Past that gate, a WiFi-configuration routine fed unsanitized text straight into a root shell. The researchers called part of the chain wormable, because a compromised robot could scan for the next Unitree device within Bluetooth range and infect it on its own, no operator involved.
Unitree had known since May 2025. The researchers' last substantive exchange with the company came in July, the same month Unitree announced plans for an initial public offering. Contact then stopped. The exploit went public that September with no vendor fix in place. By the time Unitree's IPO closed in August 2026, the flaw was still open. A month later, the same G1 model stood on a demo floor at IFA in Berlin, one of the world's largest consumer-electronics trade shows, drawing crowds while the question that had followed it for a year remained unanswered.
Robot cybersecurity has split into two industries, and which one a given machine belongs to has almost nothing to do with how much physical damage it could do.
The one that got patched
Three months before the IFA appearance, a different robot maker handled a worse-sounding bug in something close to the way enterprise software vendors have trained the world to expect. Researcher Vera Mens of Claroty's Team82 found a command-injection flaw in the Dashboard Server of Universal Robots' PolyScope 5 controller software, the interface running on collaborative arms deployed across automotive plants, electronics assembly lines, and warehouses worldwide. The flaw needed no authentication: anyone with network access to the Dashboard Server port could send a crafted string and execute commands directly on the robot's own operating system. The US Cybersecurity and Infrastructure Security Agency rated it 9.8 out of 10, close to the maximum the scoring system allows.
Universal Robots did what a coordinated disclosure process is designed to produce. It worked with Mens through CERT/CC's reporting channel, shipped PolyScope version 5.25.1 with the flaw closed, and let CISA publish the advisory, tracked as CVE-2026-8153, alongside the fix rather than ahead of it. Two months later, KUKA, one of the oldest names in industrial robotics, secured an IEC 62443-4-2 Security Level 2 certification for its own control systems, the closest thing the sector has to a recognized cybersecurity seal of approval. Neither event made much noise outside specialist circles. That is what a functioning vulnerability-disclosure market looks like: unglamorous, procedural, and mostly invisible because it works.
The one that didn't
Unitree's response followed none of that pattern. There was no coordinated CVE process, no published patch timeline, and, by the researchers' own account, no meaningful engagement from the company across five months of attempted contact. Unitree told reporters around the IFA appearance that it had acknowledged the vulnerabilities and begun addressing them, a statement of intent rather than a shipped fix. Two more root-access vulnerabilities, CVE-2026-76639 and CVE-2026-76640, became public in August 2026, adding Bluetooth, cloud-API, and Linux control-system entry points to the same product line.
A wormable bug that spreads over Bluetooth in a crowded exhibition hall is not a hypothetical. It is a description of the exact environment Unitree chose to put the affected robot back into.
Why the split tracks capital, not danger
Rank these two machines by what a successful attack could actually do, and the ranking does not favor the response each one got. A compromised PolyScope arm is a stationary manipulator, typically fenced or light-curtained, on a network a plant's own IT team is supposed to be segmenting from the internet. A compromised G1 is a mobile, camera- and microphone-equipped biped that a buyer can carry out of a trade show, connect to a home network, and expose to every other Unitree device that later comes within Bluetooth range. If physical risk were the deciding factor, the humanoid deserved the more urgent response, not the slower one.
What actually explains the gap is who each company was selling to, and what story that buyer needed to hear. Universal Robots and KUKA sell into procurement departments that require a security certification line item before a contract is signed; sitting on a critical CVE would cost them the sale, not just the headline. Unitree spent 2025 and 2026 selling into a capital market that wanted a growth story and a viral demo reel, culminating in a public offering. Acknowledging an unresolved, wormable exploit in the middle of that pitch was a cost with no buyer in the room demanding it be paid, so the company did not pay it.
Certification tracks the buyer's leverage, not the machine's risk.
The pressure that eventually showed up came from a different direction entirely. Alias Robotics researchers separately alleged that the G1 was transmitting audio, video, location, and sensor data to servers in China without operator notification, a claim Unitree disputes, saying it does not collect private or sensitive data without authorization. In the same stretch, the Pentagon linked Unitree to Chinese military-connected technology and the Federal Communications Commission added the company to its national-security Covered List. None of that response ran through a product-security process. It ran through channels that only engage once a company is large and geopolitically visible enough to be worth the paperwork, which is a far higher bar than "this robot has a wormable Bluetooth exploit."
What a buyer should actually be asking
I run a platform that tracks robot and robotics-company data for a living, which means every week I read vendor claims that a product is secure or certified with no attached evidence of what that certification actually tested. IEC 62443 and similar industrial standards were written for stationary equipment behind a defined network perimeter. They say very little about a machine that broadcasts over Bluetooth, pulls firmware updates over the open internet, and leaves the building in a buyer's rental van. A certification logo answers a narrower question than most procurement teams assume it does, and a humanoid or mobile-robot vendor can hold one while still shipping the exact class of flaw the certification was never designed to catch.
The question worth asking a vendor is not whether it holds a certificate. It is whether the company has ever shipped a security patch under outside pressure, and how long that took from first contact to fix. Universal Robots has a documented answer to that question now, timestamped and public. Unitree, more than a year after the researchers' first message, still does not.
The event that forces this two-tier system to merge will not be another CVSS score. It will be the first time a robot at a public demo, in front of cameras and a room full of buyers, gets hijacked by exactly the exploit its maker was warned about a year earlier and chose not to fix. Every trade show between now and then is a rehearsal for that moment, whether the exhibitors know it or not.
Disclaimer: This column reflects the author's own analysis and is provided for general information purposes only. It does not constitute investment, financial, legal, or cybersecurity advice. Readers should verify details with primary sources before making procurement or investment decisions. Hero image: Unitree's own official product photography of the G1 humanoid robot, via the company's website.












