CVE-2026-78251
Received Received - Intake

FTP Hardcoded Credentials in DJI Drones

Vulnerability report for CVE-2026-78251, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: CIRCL

Description

DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
dji neo to 01.00.0400 (inc)
dji neo_2 to 01.00.0500 (inc)
dji flip to 01.00.1200 (inc)
dji air_3 to 01.00.1600 (inc)
dji air_3s to 01.00.1400 (inc)
dji avata_2 to 01.00.0400 (inc)
dji avata_360 to 01.00.0300 (inc)
dji mavic_3 to 01.00.1400 (inc)
dji mavic_3_classic to 01.00.0800 (inc)
dji mavic_3_pro to 01.01.0700 (inc)
dji mavic_4_pro to 01.00.0500 (inc)
dji mini_2 to 01.07.0200 (inc)
dji mini_3 to 01.00.0500 (inc)
dji mini_3_pro to 01.00.0900 (inc)
dji mini_4_pro to 01.00.1100 (inc)
dji mini_5_pro to 01.00.0600 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves DJI drones running an FTP service with hardcoded credentials. Attackers with network or USB access can upload unlimited files to the /blackbox/upgrade/ directory, consuming storage space. This prevents the drone from recording flight data, logs, and telemetry, and may block firmware updates. Files persist even after reboot or factory reset.

Detection Guidance

Check for unauthorized FTP connections to DJI drones on your network. Use commands like 'nmap -p 21 <drone_IP>' to scan for open FTP ports. Monitor storage usage in /blackbox/upgrade/ on affected models. Look for unexpected file uploads or storage exhaustion.

Impact Analysis

If exploited, this flaw could cause your drone to lose critical flight data, crash, or fail to update firmware. It may also allow attackers to plant malicious files that persist across resets, potentially enabling further attacks. Physical access via USB or network access is required.

Mitigation Strategies

Isolate affected DJI drones from your network. Apply vendor-provided firmware updates immediately. Disable FTP service if possible or restrict access via network segmentation. Monitor storage usage regularly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78251. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart