CVE-2026-78306
Received Received - Intake

Unauthenticated Command Injection in DJI Drones via Bluetooth

Vulnerability report for CVE-2026-78306, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: CIRCL

Description

DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect to the drone's internal Wi-Fi network, potentially gaining access to the flight control interface and issuing flight commands. Crafted DUML commands can also disable or restart the Wi-Fi and Bluetooth interfaces, disconnect Wi-Fi clients, or reset wireless configuration, resulting in a denial-of-service condition that can disrupt the operator's wireless control, video, and telemetry connections during flight. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
dji neo to 01.00.0400 (inc)
dji neo_2 to 01.00.0500 (inc)
dji flip to 01.00.1200 (inc)
dji air_3 to 01.00.1600 (inc)
dji air_3s to 01.00.1400 (inc)
dji avata_2 to 01.00.0400 (inc)
dji avata_360 to 01.00.0300 (inc)
dji mavic_3 to 01.00.1400 (inc)
dji mavic_3_classic to 01.00.0800 (inc)
dji mavic_3_pro to 01.01.0700 (inc)
dji mavic_4_pro to 01.00.0500 (inc)
dji mini_2 to 01.07.0200 (inc)
dji mini_3 to 01.00.0500 (inc)
dji mini_3_pro to 01.00.0900 (inc)
dji mini_4_pro to 01.00.1100 (inc)
dji mini_5_pro to 01.00.0600 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves DJI drones exposing an unauthenticated DUML command interface over Bluetooth. An attacker within Bluetooth range can modify Wi-Fi settings like SSID, password, MAC address, and regulatory country code. They can set a known Wi-Fi password to gain access to the drone's internal network and flight control interface, potentially issuing unauthorized flight commands. Attackers can also disable Wi-Fi or Bluetooth, disconnect clients, or reset configurations, causing denial-of-service conditions that disrupt the operator's control, video, and telemetry during flight.

Detection Guidance

Detection involves monitoring for unauthorized Bluetooth connections to affected DJI drones and checking for unexpected changes in Wi-Fi configuration. Use Bluetooth scanning tools like hcitool or bluetoothctl to detect active connections. Inspect Wi-Fi settings on the drone for unusual SSID, PSK, or MAC address modifications. Monitor network traffic for unauthorized access to the drone's internal Wi-Fi network.

Impact Analysis

If you own or operate an affected DJI drone, an attacker could take control of your drone, disrupt its operations, or steal sensitive data transmitted over Wi-Fi. They might intercept video feeds, telemetry, or even send malicious commands to alter the drone's flight path. Additionally, denial-of-service attacks could cause the drone to lose connection, leading to crashes or loss of control.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data transmitted by the drone, such as video feeds or telemetry, potentially violating data protection regulations like GDPR or HIPAA. Unauthorized control of the drone may also result in breaches of operational security or privacy laws, depending on the use case and jurisdiction.

Mitigation Strategies

Apply the latest firmware update from DJI to patch the vulnerability. Disable Bluetooth and Wi-Fi interfaces when not in use. Avoid operating the drone in areas with potential unauthorized access. Regularly check for firmware updates and monitor drone configuration changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78306. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart