Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78255— DJI Drone HTTP Media Server Allows Unauthenticated Access to Stored Media

Quick assessment

Affected
DJI Neo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

DJI 无人机上运行的 HTTP 媒体服务器通过 端点提供存储的照片和视频,且未对请求客户端进行身份验证。文件名遵循可预测的模式,使得攻击者加入无人机内部网络后,能够枚举有效的文件名并窃取存储的照片和视频。泄露的媒体内容可能包含敏感信息,包括私人位置、财产信息、旅行历史、可识别的个体身份以及操作员的日常习惯。 受影响的型号及版本如下: DJI Neo,版本低于 01.00.0400 DJI Neo 2,版本低于 01.00.0500 DJI Flip,版本低于 01.00.1200 DJI Air 3,版本低于 0

CVSS 8.7 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78255

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DJI Drone HTTP Media Server Allows Unauthenticated Access to Stored Media
Source: CVE Program / CVE List V5
Vulnerability Description
The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a predictable pattern, allowing an attacker who joins the drone's internal network to enumerate valid filenames and exfiltrate stored photos and videos. The exposed media may reveal sensitive information, including private locations, property, travel history, identifiable individuals, and the operator's routines. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
DJI Neo 0 ~ 01.00.0400 -
DJI Neo 2 0 ~ 01.00.0500 -
DJI Flip 0 ~ 01.00.1200 -
DJI Air 3 0 ~ 01.00.1600, -
DJI Air 3S 0 ~ 01.00.1400 -
DJI Avata 2 0 ~ 01.00.0400 -
DJI Avata 360 0 ~ 01.00.0300 -
DJI Mavic 3 0 ~ 01.00.1400 -
DJI Mavic 3 Classic 0 ~ 01.00.0800 -
DJI Mavic 3 Pro 0 ~ 01.01.0700 -
DJI Mavic 4 Pro 0 ~ 01.00.0500 -
DJI Mini 2 0 ~ 01.07.0200 -
DJI Mini 3 0 ~ 01.00.0500 -
DJI Mini 3 Pro 0 ~ 01.00.0900 -
DJI Mini 4 Pro 0 ~ 01.00.1100 -
DJI Mini 5 Pro 0 ~ 01.00.0600 -

II. Public POCs for CVE-2026-78255

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78255

登录查看更多情报信息。

Vendor Pages for CVE-2026-78255 (1)

Same Patch Batch · DJI · 2026-08-24 · 4 CVEs total

CVE-2026-78251 9.3 CRITICAL DJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox Directory
CVE-2026-78306 8.5 HIGH DJI Drone Bluetooth Interface Unauthenticated DUML Command Execution
CVE-2026-78321 6.0 MEDIUM DJI Drone HTTP Media Server Denial of Service via Connection Pool Exhaustion

IV. Related Vulnerabilities

V. Comments for CVE-2026-78255

No comments yet


Leave a comment