Denial of Service Vulnerability in DJI Drones Caused by Improper Connection Management
CVE-2026-78321

6MEDIUM

Key Information:

Vendor

Dji

Status
Neo
Neo 2
Flip
Air 3
Vendor
CVE Published:
24 August 2026

What is CVE-2026-78321?

The HTTP media server on certain DJI drones fails to enforce sufficient limits on incoming connections or request rates. An attacker with access to the internal network can overwhelm the server's connection pool by continuously requesting a stored media file. This attack results in a denial of service, obstructing the legitimate retrieval of media from the drone through the DJI Fly application, particularly in QuickTransfer mode. To mitigate this vulnerability, affected users must perform a firmware update provided by the vendor.

Affected Version(s)

Air 3 0 <= 01.00.1600

Air 3S 0 <= 01.00.1400

Avata 2 0 <= 01.00.0400

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdelrahman Yousef
Dr. Jordan Samhi
.