Command Injection Vulnerability in DJI Mavic 2 Remote Controller
CVE-2020-29664
7.8HIGH
What is CVE-2020-29664?
The DJI Mavic 2 Remote Controller is susceptible to a command injection vulnerability that allows for arbitrary code execution. This vulnerability arises from inadequate validation of firmware upgrade packets. Attackers could exploit this flaw by sending a specially crafted firmware packet to the controller, potentially compromising its functionality. It is crucial for users to update to firmware version 01.00.0510 or later to mitigate this risk.
