Denial of Service Vulnerability in DJI Drones Caused by Improper Connection Management
CVE-2026-78321
6MEDIUM
What is CVE-2026-78321?
The HTTP media server on certain DJI drones fails to enforce sufficient limits on incoming connections or request rates. An attacker with access to the internal network can overwhelm the server's connection pool by continuously requesting a stored media file. This attack results in a denial of service, obstructing the legitimate retrieval of media from the drone through the DJI Fly application, particularly in QuickTransfer mode. To mitigate this vulnerability, affected users must perform a firmware update provided by the vendor.
Affected Version(s)
Air 3 0 <= 01.00.1600
Air 3S 0 <= 01.00.1400
Avata 2 0 <= 01.00.0400
References
CVSS V4
Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdelrahman Yousef
Dr. Jordan Samhi
