FTP Vulnerability in DJI Drones Allows Unrestricted File Uploads
CVE-2026-78251

9.3CRITICAL

Key Information:

Vendor

Dji

Status
Neo
Neo 2
Flip
Air 3
Vendor
CVE Published:
24 August 2026

What is CVE-2026-78251?

DJI drones are affected by a security issue involving a hardcoded FTP service allowing authenticated users to upload files without restrictions on size or quantity. Attackers with network access can exploit this vulnerability to fill up the device's storage, obstructing the logging of flight records and telemetry data, and hindering firmware updates. This issue impacts a wide range of DJI models and persists even after device reboots or factory resets, necessitating immediate attention and firmware updates from the manufacturer.

Affected Version(s)

Air 3 0 <= 01.00.1600

Air 3S 0 <= 01.00.1400

Avata 2 0 <= 01.00.0400

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdelrahman Yousef
Dr. Jordan Samhi
.