CVE-2026-78321
Received Received - Intake

Denial of Service in DJI Drone HTTP Media Server

Vulnerability report for CVE-2026-78321, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: CIRCL

Description

The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media file, preventing the server from handling legitimate requests and causing a denial of service that prevents the DJI Fly application from retrieving photos and videos from the aircraft in QuickTransfer mode. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
dji neo to 01.00.0400 (exc)
dji neo_2 to 01.00.0500 (exc)
dji flip to 01.00.1200 (exc)
dji air_3 to 01.00.1600 (exc)
dji air_3s to 01.00.1400 (exc)
dji avata_2 to 01.00.0400 (exc)
dji avata_360 to 01.00.0300 (exc)
dji mavic_3 to 01.00.1400 (exc)
dji mavic_3_classic to 01.00.0800 (exc)
dji mavic_3_pro to 01.01.0700 (exc)
dji mavic_4_pro to 01.00.0500 (exc)
dji mini_2 to 01.07.0200 (exc)
dji mini_3 to 01.00.0500 (exc)
dji mini_3_pro to 01.00.0900 (exc)
dji mini_4_pro to 01.00.1100 (exc)
dji mini_5_pro to 01.00.0600 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service issue in DJI drones where the HTTP media server lacks proper connection or request rate limits. An attacker on the drone's internal network can repeatedly request a stored media file, exhausting the server's connection pool. This prevents the server from handling legitimate requests, blocking the DJI Fly app from retrieving photos and videos in QuickTransfer mode.

Detection Guidance

Detect unusual network traffic targeting the DJI drone's HTTP media server. Monitor for repeated requests to stored media files or connection pool exhaustion. Use network tools like tcpdump or Wireshark to capture traffic on the drone's internal network interface.

Impact Analysis

If exploited, this vulnerability could prevent you from accessing media files on your drone via the DJI Fly app. It may also disrupt normal drone operations by overwhelming the media server, leading to unresponsive applications and potential loss of control during flight.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by disrupting the availability of media files stored on DJI drones. A denial of service could prevent authorized users from accessing necessary data, which may violate requirements for timely data retrieval and availability under these regulations.

Mitigation Strategies

Apply the latest firmware update from DJI to affected drone models. Isolate the drone's network from untrusted devices. Disable QuickTransfer mode until the update is applied. Monitor for signs of ongoing exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78321. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart