Unitree G1 EDU firmware versions through 1.5.2 contain a critical unauthenticated remote code execution vulnerability tracked as CVE-2026-76639. The vulnerability is exploitable by network-adjacent attackers through a chain of three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API. Attackers can leverage these weaknesses to publish DDS control messages that restart the bashrunner service, plant malicious payloads via path traversal, and trigger their execution as root (uid 0). The attack chain ultimately grants full root-level command execution on the affected robotic platform. This vulnerability poses significant risk to deployments of the Unitree G1 EDU robot in research or educational environments. Public proof-of-concept code and detailed technical write-ups are available, increasing exploitation likelihood.