CVE-2026-77812
Received Received - Intake

Information Disclosure in DJI Drones via BLE

Vulnerability report for CVE-2026-77812, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-21

Last updated on: 2026-08-21

Assigner: CIRCL

Description

DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to QuickTransfer mode, the DJI Fly application exchanges DUML messages with the drone over BLE, including the Wi-Fi credentials. An attacker within BLE range can passively sniff this traffic and recover the credentials in cleartext, including the drone's Wi-Fi PSK, SSID, and trusted identifier UUID. Obtaining these credentials allows the attacker to join the drone's internal Wi-Fi network, interact with network services exposed by the drone, and decrypt Wi-Fi traffic exchanged between the drone and the legitimate user. * An attacker within BLE range recovers the Wi-Fi SSID and PSK in cleartext, and can then join the drone's network * The same capture also exposes the session UUID identifier, which is the only thing the drone uses to tell a trusted client from an unknown one, so the attacker can replay it and skip the physical confirmation of new connected devices. * The credentials do not change between sessions unless the operator manually resets the Wi-Fi settings, so one capture stays valid indefinitely * The attack is fully passive, with nothing transmitted and no connection made, so neither the operator nor the drone has any indication the session was observed * A BLE sniffer and presence during one normal DJI Fly connection are needed Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor. There is no user-side mitigation that fully addresses the vulnerability without upgrading.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-21
Last Modified
2026-08-21
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
dji neo to 01.00.0400 (inc)
dji neo_2 to 01.00.0500 (inc)
dji flip to 01.00.1200 (inc)
dji air_3 to 01.00.1600 (inc)
dji air_3s to 01.00.1400 (inc)
dji avata_2 to 01.00.0400 (inc)
dji avata_360 to 01.00.0300 (inc)
dji mavic_3 to 01.00.1400 (inc)
dji mavic_3_classic to 01.00.0800 (inc)
dji mavic_3_pro to 01.01.0700 (inc)
dji mavic_4_pro to 01.00.0500 (inc)
dji mini_2 to 01.07.0200 (inc)
dji mini_3 to 01.00.0500 (inc)
dji mini_3_pro to 01.00.0900 (inc)
dji mini_4_pro to 01.00.1100 (inc)
dji mini_5_pro to 01.00.0600 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-311 The product does not encrypt sensitive or critical information before storage or transmission.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

DJI drones use an unencrypted protocol called DUML over Bluetooth Low Energy (BLE) to exchange Wi-Fi credentials with the DJI Fly app. An attacker within BLE range can passively capture these credentials in cleartext, including the drone's Wi-Fi network name, password, and session identifier. This allows the attacker to join the drone's network, access its services, and decrypt traffic without detection.

Detection Guidance

This vulnerability is passive and requires monitoring BLE traffic near the drone during DJI Fly app connections. Use a BLE sniffer like Ubertooth or Wireshark with BLE support to capture DUML protocol messages. Look for unencrypted Wi-Fi credential exchanges between the drone and app.

Impact Analysis

An attacker could gain unauthorized access to your drone's Wi-Fi network, intercept sensitive data transmitted between the drone and your device, or even spoof the drone's trusted identifier to bypass security controls. The attack is passive, leaving no trace, and the credentials remain valid until manually reset.

Compliance Impact

This vulnerability could lead to unauthorized access to drone Wi-Fi networks, potentially exposing sensitive data transmitted between the drone and legitimate users. This may violate data protection requirements under GDPR (e.g., unauthorized access to personal data) and HIPAA (e.g., exposure of health-related data if drones are used in medical contexts).

Mitigation Strategies

Update your DJI drone firmware to the latest version immediately. Avoid using QuickTransfer mode or connecting to the drone's Wi-Fi network in public areas. Manually reset Wi-Fi settings if credentials may have been exposed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77812. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart