FTP Vulnerability in DJI Drones Allows Unrestricted File Uploads
CVE-2026-78251
9.3CRITICAL
What is CVE-2026-78251?
DJI drones are affected by a security issue involving a hardcoded FTP service allowing authenticated users to upload files without restrictions on size or quantity. Attackers with network access can exploit this vulnerability to fill up the device's storage, obstructing the logging of flight records and telemetry data, and hindering firmware updates. This issue impacts a wide range of DJI models and persists even after device reboots or factory resets, necessitating immediate attention and firmware updates from the manufacturer.
Affected Version(s)
Air 3 0 <= 01.00.1600
Air 3S 0 <= 01.00.1400
Avata 2 0 <= 01.00.0400
