2026-09-05/No.041第 041 期/Brief精简版
EMBODIED RED-TEAM BRIEFING · Saturday · Light

Embodied & Unmanned Red-Team Briefing

Embodied & Unmanned Red-Team Briefing · 2026-09-05 · Issue 041 · Brief
Injury / Loss of control
2
Today
Individual platform takeover
1
Today
Functional failure
1
Today
Intelligence / Theory
1
Today

Red-team action board

NOW
  • Unitree Go2 unauthenticated DDS DataWriter root RCE, CVE-2026-27509/27510: mass quadruped-takeover risk
  • Everon/ev.energy unauthenticated OCPP WebSocket impersonation, CVSS 9.4: fleet-wide charger DoS reproducible
WEEK
  • Commercial-quadruped VLA jailbreaks reach 100% success; humanoid transfer needs bench validation
  • PX4 CVE-2026-1579 fleet upgrade/signing audit remains incomplete
RANGE
  • Unitree → isolated network/used hardware; no exhibitions or public settings
  • OCPP → laboratory charger/mock backend; no real grid

§3 Robot stacks and buses

ROS 2/DDS · Unitree Embodied Platforms
Unitree Go2 unauthenticated DDS DataWriter root shell, CVE-2026-27509/27510
Injury / Loss of control
Public PoC Trusted Business relevance boschko.ca · 2026-09-05
ref CVE-2026-27509 (V1.1.7) · CVE-2026-27510 (V1.1.11) · Same-network DDS probes/Android local database · Nearby WiFi/Ethernet access · Under $100
Link hijack → stack control → execution: abuse of rt/api/programming_actuator/* DDS executes arbitrary Python as root. CVE-27510 achieves the same through local Android Blockly action blocks. Surface spans the Unitree ecosystem.
Reproduction notes : Expected effects: full takeover, arbitrary motion/surveillance. Isolated sites/used hardware only; never crowds, exhibitions or customer demonstrations.
Source →

§6 Cloud-to-device and queues

Charger Backends · OCPP
Continuing OCPP disclosures: Everon CVSS 9.4 and ev.energy/SWTCH CVEs permit unauthenticated charger impersonation
Injury / Loss of control
Public PoC Verified Business relevance CISA ICSA-26-057-06/07 · 062-08 · 2026-09-05
ref CVE-2026-27772/24445/26290/25774 · ICSA-26-057-07 · 062-08 · WebSocket client and known station ID · Remote/network reachable · Under $100
Cloud–device → execution: IDs accepted without authentication permit impersonation, session preemption, billing changes and mass DoS. Related SWTCH flaws redirect legitimate traffic through hijacked sessions.
Reproduction notes : Expected effects: network-wide outages, billing contamination and session takeover. Sandbox lab chargers/mock backend only; no real grid/operating chargers.
Source →

§2 Communication-link hijacking

MAVLink · PX4 · Long-tail Tracking
PX4 CVE-2026-1579 SERIAL_CONTROL shell remains CVSS 9.8; fleet signing adoption needs assessment
Individual platform takeover
Public PoC Verified Business relevance CISA ICSA-26-090-02 · 2026-09-05, long-tail
ref CVE-2026-1579 · Generic GCS and reachable PX4 · Remote, WiFi/UDP/serial link required · Under $100
Link hijack → stack control: unsigned MAVLink permits interactive shell via SERIAL_CONTROL. Multiple reports this week describe incomplete remediation; retained in WEEK.
Reproduction notes : Expected effects: takeover/mission changes. Isolated PX4 SITL/Gazebo only; no real-aircraft chain.
Source →

§4 Autonomous decisions and embodied agents

VLA · Jailbreaks into Physical Actions
30 new embodied-agent attacks this year: Go2 VLA jailbreaks reach 100%, inducing surveillance/collisions
Functional failure
Public PoC Verified Sector signal arXiv 2608.16843 / 2605.02900 · 2026-09-05
ref arXiv 2608.16843 survey: 58 attacks/61 defenses as of 2026-08-15 · Target robot, voice/text injection and patches · Nearby · Under $100
Decision hijack → execution: VLA predictions use observation history, so one poisoned frame can affect a trajectory. Maximum reported Go2 surveillance/collision success highlights action-alignment gaps.
Reproduction notes : Expected effects: unauthorized motion/surveillance. Enclosed sites, soft protection and emergency stop only; no public settings or other people present.
Source →

§8 Exposure Intelligence, International & China

RECON · Statistics only
RECON · Statistics only · No locatable assets
CNVD: 336 new flaws, 168 High; connected-vehicle/drone share remains 5–8%
Intelligence / Theory
Community Sector signal CN-SEC / CNVD weekly report · 2026-09-05
ref CNVD week 18 figures · 336/168/121/47 · Authorized mapping account · Range — · Cost —
Statistics only: a small share of new High flaws concerns T-BOX/TSP and industrial-drone ground stations. Categories/scale support tracking; no asset fingerprints.
Reproduction notes : Categories/estimates only; no identifiable IPs, fingerprints or paths.
Source →

Long-tail tracking

  • Across Unitree models : Assess whether G1/H1 humanoids share Go2's programming_actuator channel through bench comparison this week.
  • Eight UDS transport attacks : VehicleSec 2024 bench methods still lack public vendor fix notices; await new CNVD assignments.
  • PX4 CVE-2026-1579 remediation coverage : Signing status assessed through passive observation; preparing SITL scripts to monitor default-setting changes.
  • OCPP impersonation chain : Track CSMS authentication hotfixes from Everon, ev.energy and SWTCH.
  • VLA defenses : 61 new defense works in 2026, but few open action-alignment/refusal implementations. Consider next week's deep analysis.
EMBODIED RED-TEAM BRIEFING · Saturday · Light

具身 / 无人系统安全红队速报

Embodied & Unmanned Red-Team Briefing · 2026-09-05 · 第 041 期 · 精简版
致伤/失控
2
当日
单体接管
1
当日
功能失效
1
当日
情报/理论
1
当日

红队行动板

NOW
  • Unitree Go2 · DDS DataWriter 未鉴权 RCE 到 root(CVE-2026-27509/27510),机器狗批量接管风险
  • OCPP 后端 · Everon / EV Energy 无鉴权 WebSocket 冒充充电站(CVSS 9.4),全网桩批量拒服可复现
WEEK
  • VLA 越狱在商用机器狗 100% 成功率,人形本体迁移路径需台架验证
  • PX4 CVE-2026-1579 MAVLink 无认证 shell 仍未完成机队升级排查
RANGE
  • Unitree 复现 → 隔离网段 + 二手机型;禁在展会/公共环境验证
  • OCPP 冒充 → 实验室桩样 + mock backend;禁连真实电网

§3 机器人栈与总线

ROS2·DDS · Unitree 具身平台
Unitree Go2 机器狗 · DDS 未鉴权 DataWriter 直取 root shell(CVE-2026-27509 / 27510)
致伤/失控
PoC 公开 Trusted 业务相关 boschko.ca · 2026-09-05
ref CVE-2026-27509 (V1.1.7) · CVE-2026-27510 (V1.1.11) · 装备 同网段 DDS 探测脚本 / Android 应用本地 DB · 距离 近场(同 Wi-Fi/以太网段) · 需入网 · 成本 <$100
链路劫持 → 栈内控制 → 物理执行:滥用 rt/api/programming_actuator/* DDS 通道以 root 执行任意 Python;27510 通过篡改 Android 应用本地 Blockly 动作块达同效。攻击面为整个 Unitree 生态。
复现要点:预期物理效果:机器狗完全接管,可下发任意运动动作或做监控收集;仅在隔离场地 + 二手机型上验证,禁在人群 / 展会 / 客户现场演示时打链。
来源 →

§6 云-端与队列

充电桩后端 · OCPP
OCPP 后端持续披露 · Everon CVSS 9.4 与 EV Energy / SWTCH 四 CVE 均允许无鉴权冒充充电站
致伤/失控
PoC 公开 Verified 业务相关 CISA ICSA-26-057-06/07 · 062-08 · 2026-09-05
ref CVE-2026-27772/24445/26290/25774 · ICSA-26-057-07 · 062-08 · 装备 OCPP WebSocket 客户端 + 已知站点 ID · 距离 远场 · 网络可达 · 成本 <$100
云-端 → 物理执行:WebSocket 端点接收已知 / 可枚举站点 ID 且不做鉴权 → 冒充为合法 charger 抢占会话、篡账单、批量拒服。SWTCH 侧同类问题使会话可劫持并把合法流量导向攻手。
复现要点:预期物理效果:全网桩拒服、账单被投毒、单站会话被抢占;仅在带 sandbox 的实验室桩样与 mock backend 上验证,禁连真实电网侧或运营桩。
来源 →

§2 通信链路劫持

MAVLink · PX4 · 长尾跟进
PX4 CVE-2026-1579 · MAVLink SERIAL_CONTROL 无认证取 shell 依旧 9.8 分,机队签名启用率待评估
单体接管
PoC 公开 Verified 业务相关 CISA ICSA-26-090-02 · 2026-09-05(长尾)
ref CVE-2026-1579 · 装备 任意 MAVLink 地面站 + PX4 可达网络 · 距离 远场 · 需入链路(Wi-Fi/UDP/串口) · 成本 <$100
链路劫持 → 栈内控制:MAVLink 默认未签名,攻手直接向机身发 SERIAL_CONTROL 拿交互 shell;周内多家安全媒体确认修复面不完整,本条继续挂 WEEK。
复现要点:预期物理效果:单机完全接管 / mission 篡改;PX4 SITL + Gazebo 隔离验证,禁真机开链。
来源 →

§4 自主决策与具身 Agent

VLA · 越狱转物理动作
具身 Agent 攻击年内 30 条新记录 · Unitree Go2 上 VLA 越狱 100% 成功、可诱发监控与碰撞
功能失效
PoC 公开 Verified 赛道信号 arXiv 2608.16843 / 2605.02900 · 2026-09-05
ref arXiv 2608.16843 综述(截至 2026-08-15 汇总 58 攻击 / 61 防御) · 装备 目标本体 + 语音/文本注入 + 对抗贴纸 · 距离 近场 · 成本 <$100
决策劫持 → 物理执行:VLA 动作预测挂全观测历史,一帧被投毒可影响整条轨迹;商用 Go2 上诱发监控 / 碰撞的成功率触顶,说明动作层对齐仍是空档。
复现要点:预期物理效果:越权动作 / 监控采集;仅在封闭场地 + 软保护 + 常备急停下做,禁公共环境或有他人在场。
来源 →

§8 暴露情报(国际+国内)

RECON · 仅统计层
RECON · 仅统计层 · 不给可定位资产
CNVD 本周新增 336 条 · 高危 168 · 车联网 / 无人机相关比例继续在 5-8% 区间
情报/理论
Community 赛道信号 CN-SEC / CNVD 周报 · 2026-09-05
ref CNVD 周报第 18 期口径 · 336/168/121/47 · 装备 合法测绘账号 · 距离 — · 成本 —
仅统计层:国内周内新增高危里,含少量车联网 T-BOX / TSP 相关条目与工业无人机地面站类。类别与规模满足赛道跟踪需要,不给具体资产指纹。
复现要点:仅提供类别 + 规模约数,不给可定位 IP / 指纹 / 访问路径。
来源 →

长尾追踪

  • Unitree 系全线:Go2 之外的 G1 / H1 人形本体是否共用同套 programming_actuator 通道,本周内需要台架比对。
  • UDS 传输层 8 类攻击:VehicleSec 2024 论文的台架复现方案仍未有厂商侧公开修复通告,等待新一轮 CNVD 挂号。
  • PX4 CVE-2026-1579 修复面:MAVLink v2 签名启用与否只能通过被动嗅探判定,正在准备 SITL 侧的默认开关变更观察脚本。
  • OCPP 冒充链:CSMS 侧鉴权补丁发布节奏,需关注 Everon / EV Energy / SWTCH 三家的 hotfix 公告。
  • VLA 防御:2026 内新增 61 个防御工作,其中动作层对齐 / 拒动作规则的开源实现有限,值得下周深度版拆解一次。
Red-team research only; validate solely in isolated simulation or controlled ranges.仅供红队研判;验证须在隔离仿真或封闭受控场地进行。Views: 阅读量:
All material is aggregated from public disclosures. If any content infringes your rights, contact us and it will be removed.全部内容均整理自公开披露;若有侵权,请联系我们删除。
Copyright © 2026 ExploitLabs. All rights reserved. · Contact: contact@exploitlabs.ai · exploitlabs.ai版权所有 © 2026 ExploitLabs · 保留所有权利 · 联系方式:contact@exploitlabs.ai · exploitlabs.ai