Unauthorized Media Access in DJI Drones Affects Multiple Models
CVE-2026-78255
8.7HIGH
What is CVE-2026-78255?
A vulnerability exists in the HTTP media server of DJI drones where stored photos and videos are accessible via the /v2 endpoint without client authentication. This allows unauthorized users who can connect to the drone's internal network to systematically list and exfiltrate media files. The leaked materials can contain sensitive information such as private locations, personal identities, travel habits, and operational details of the drone users, leading to substantial privacy and security risks.
Affected Version(s)
Air 3 0 <= 01.00.1600,
Air 3S 0 <= 01.00.1400
Avata 2 0 <= 01.00.0400
