<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Embedded on CuraSec</title><link>https://curasec.metacog.co.kr/tags/embedded/</link><description>Recent content in Embedded on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 28 Aug 2026 21:21:40 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/embedded/index.xml" rel="self" type="application/rss+xml"/><item><title>Unitree G1 EDU Robot: Dual Root RCE Flaws, One via Bluetooth</title><link>https://curasec.metacog.co.kr/insights/2026-08-28-two-unitree-g1-edu-humanoid-robot-flaws-enable-root-rce-one/</link><pubDate>Fri, 28 Aug 2026 21:21:40 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-28-two-unitree-g1-edu-humanoid-robot-flaws-enable-root-rce-one/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your environment uses Unitree G1 EDU robots, review network segmentation and disable unnecessary BLE/network services; no KEV listing and near-zero EPSS suggest limited active exploitation pressure, but public PoCs exist so schedule patching.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-76639 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub · CVE-2026-76640 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>Entropy Bootstrapping Defense Path Proposed for ESP32 IoT Nodes</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-entropy-bootstrapping-for-wireless-embedded-systems/</link><pubDate>Mon, 13 Jul 2026 14:30:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-entropy-bootstrapping-for-wireless-embedded-systems/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Solid research demonstrating that ESP32 WDEV output is pseudorandom when RF is disabled yet passes statistical tests — a reminder that output testing is insufficient for source-state validation. Worth reviewing if your team ships ESP32-based IoT products; no patch or CVE to act on yet.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>