Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78251— DJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox Directory

Quick assessment

Affected
DJI Neo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

大疆(DJI)无人机包含一个使用硬编码凭证的FTP服务,该凭证在受影响的型号中共享。此服务允许经过认证的用户无限制地上传文件,在文件尺寸、文件数量或总存储占用方面均无限制,并且可以在 目录中上传文件以及覆盖该目录中的现有文件。拥有无人机内部网络或USB RNDIS接口访问权限的攻击者可以耗尽可用存储空间,从而阻止飞机写入飞行记录、日志和遥测数据,并可能阻止后续固件更新。上传的文件在重启和恢复出厂设置后仍然保留。 受影响的型号包括: DJI Neo 直至版本 01.00.0400 DJI Neo 2 直至版本 01.

CVSS 9.3 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78251

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox Directory
Source: CVE Program / CVE List V5
Vulnerability Description
DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的凭证
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
DJI Neo 0 ~ 01.00.0400 -
DJI Neo 2 0 ~ 01.00.0500 -
DJI Flip 0 ~ 01.00.1200 -
DJI Air 3 0 ~ 01.00.1600 -
DJI Air 3S 0 ~ 01.00.1400 -
DJI Avata 2 0 ~ 01.00.0400 -
DJI Avata 360 0 ~ 01.00.0300 -
DJI Mavic 3 0 ~ 01.00.1400 -
DJI Mavic 3 Classic 0 ~ 01.00.0800 -
DJI Mavic 3 Pro 0 ~ 01.01.0700 -
DJI Mavic 4 Pro 0 ~ 01.00.0500 -
DJI Mini 2 0 ~ 01.07.0200 -
DJI Mini 3 0 ~ 01.00.0500 -
DJI Mini 3 Pro 0 ~ 01.00.0900 -
DJI Mini 4 Pro 0 ~ 01.00.1100 -
DJI Mini 5 Pro 0 ~ 01.00.0600 -

II. Public POCs for CVE-2026-78251

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78251

登录查看更多情报信息。

Other References for CVE-2026-78251 (1)

Same Patch Batch · DJI · 2026-08-24 · 4 CVEs total

CVE-2026-78255 8.7 HIGH DJI Drone HTTP Media Server Allows Unauthenticated Access to Stored Media
CVE-2026-78306 8.5 HIGH DJI Drone Bluetooth Interface Unauthenticated DUML Command Execution
CVE-2026-78321 6.0 MEDIUM DJI Drone HTTP Media Server Denial of Service via Connection Pool Exhaustion

IV. Related Vulnerabilities

V. Comments for CVE-2026-78251

No comments yet


Leave a comment