Bluetooth Vulnerability in DJI Drones Exposes Wi-Fi Settings
CVE-2026-78306
Key Information:
Badges
What is CVE-2026-78306?
CVE-2026-78306 is a critical vulnerability affecting various models of DJI drones, which are widely used for aerial photography, mapping, and surveillance. The vulnerability arises from an unauthenticated DUML command interface that is exposed over Bluetooth, allowing potential attackers within range to manipulate vital Wi-Fi configuration settings. By exploiting this vulnerability, an attacker can change parameters such as the SSID, PSK, and MAC address, or even alter the regulatory country code and wireless channel. This unauthorized access can lead to serious consequences, including the ability to connect to the drone's internal Wi-Fi network and gain control over its flight operations. Furthermore, attackers could issue flight commands or disrupt the drone’s connectivity by disabling or restarting Wi-Fi and Bluetooth interfaces, thus creating a denial-of-service scenario that impairs the operator's control and access during flight.
Affected models include multiple iterations across the DJI Neo, Mavic, Mini, and Avata product lines, with firmware updates needed to rectify the issue.
Potential impact of CVE-2026-78306
-
Unauthorized Control of Drones: Attackers may gain the capability to modify Wi-Fi settings, enabling unauthorized connection to the drone. This could allow them to manipulate flight commands, posing risks to both the drone and the surrounding environment.
-
Denial of Service: By executing crafted DUML commands, an attacker could disable essential communication interfaces, resulting in loss of control and video feed. This disruption can lead to unsafe operations and increase the risk of crashes or accidents.
-
Data and Privacy Risks: With control over the drone’s internal Wi-Fi network, an attacker could potentially intercept and access sensitive data transmitted from the drone. This exposure raises serious privacy and security concerns, especially when drones are used for mapping or surveillance tasks.
Affected Version(s)
Air 3 0 <= 01.00.1600
Air 3S 0 <= 01.00.1400
Avata 2 0 <= 01.00.0400
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
