CVE-2026-78255
Received Received - Intake

Information Disclosure in DJI Drone Media Server

Vulnerability report for CVE-2026-78255, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: CIRCL

Description

The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a predictable pattern, allowing an attacker who joins the drone's internal network to enumerate valid filenames and exfiltrate stored photos and videos. The exposed media may reveal sensitive information, including private locations, property, travel history, identifiable individuals, and the operator's routines. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
dji neo to 01.00.0400 (inc)
dji neo_2 to 01.00.0500 (inc)
dji flip to 01.00.1200 (inc)
dji air_3 to 01.00.1600 (inc)
dji air_3s to 01.00.1400 (inc)
dji avata_2 to 01.00.0400 (inc)
dji avata_360 to 01.00.0300 (inc)
dji mavic_3 to 01.00.1400 (inc)
dji mavic_3_classic to 01.00.0800 (inc)
dji mavic_3_pro to 01.01.0700 (inc)
dji mavic_4_pro to 01.00.0500 (inc)
dji mini_2 to 01.07.0200 (inc)
dji mini_3 to 01.00.0500 (inc)
dji mini_3_pro to 01.00.0900 (inc)
dji mini_4_pro to 01.00.1100 (inc)
dji mini_5_pro to 01.00.0600 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an unauthenticated HTTP media server on DJI drones that exposes stored photos and videos through the /v2 endpoint. Attackers on the drone's internal network can guess filenames to access and steal media files without permission.

Detection Guidance

Check if the drone's HTTP media server is accessible on the internal network by scanning for open ports 80 or 8080. Use commands like 'nmap -p 80,8080 <drone_IP>' to detect the service. If the /v2 endpoint responds without authentication, the vulnerability is present.

Impact Analysis

Unauthorized access to media files could reveal sensitive information like private locations, travel history, identifiable people, or the operator's routines. This may lead to privacy breaches or physical security risks.

Compliance Impact

This vulnerability may lead to unauthorized access to sensitive media files, including personal data and identifiable individuals, which could violate GDPR's data protection requirements for privacy and security. It may also breach HIPAA if protected health information is exposed through the drone's stored media.

Mitigation Strategies

Disable the drone's Wi-Fi or network access when not in use. Update the drone firmware to the latest version if patches are available. Avoid connecting to untrusted networks with the drone.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78255. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart