Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78306— DJI Drone Bluetooth Interface Unauthenticated DUML Command Execution

Quick assessment

Affected
DJI Neo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

大疆(DJI)无人机暴露了一个未经身份验证的 DUML 命令接口,该接口通过蓝牙开放。攻击者只要在蓝牙覆盖范围内,即可修改 Wi-Fi 配置参数,包括 SSID(网络名称)、PSK(预共享密钥/密码)、MAC 地址、监管国家/地区代码以及无线信道。攻击者可以将 Wi-Fi 的 PSK overwritten 为已知值,并连接到无人机内部的 Wi-Fi 网络,从而可能获得对飞行控制接口的访问权限,并下发飞行指令。 此外,精心构造的 DUML 命令还可以禁用或重启 Wi-Fi 和蓝牙接口、断开 Wi-Fi 客户端连接,

CVSS 8.5 · High EPSS 0.15% · P4

Affected Version Matrix 16

VendorProduct Version RangeStatus
DJI Air 3 ≤ 01.00.1600 affected
DJI Air 3S ≤ 01.00.1400 affected
DJI Avata 2 ≤ 01.00.0400 affected
DJI Avata 360 ≤ 01.00.0300 affected
DJI Flip ≤ 01.00.1200 affected
DJI Mavic 3 ≤ 01.00.1400 affected
DJI Mavic 3 Classic ≤ 01.00.0800 affected
DJI Mavic 3 Pro ≤ 01.01.0700 affected
DJI Mavic 4 Pro ≤ 01.00.0500 affected
DJI Mini 2 ≤ 01.07.0200 affected
DJI Mini 3 ≤ 01.00.0500 affected
DJI Mini 3 Pro ≤ 01.00.0900 affected
DJI Mini 4 Pro ≤ 01.00.1100 affected
DJI Mini 5 Pro ≤ 01.00.0600 affected
DJI Neo ≤ 01.00.0400 affected
DJI Neo 2 ≤ 01.00.0500 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78306

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
DJI Drone Bluetooth Interface Unauthenticated DUML Command Execution
Source: CVE Program / CVE List V5
Vulnerability Description
DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect to the drone's internal Wi-Fi network, potentially gaining access to the flight control interface and issuing flight commands. Crafted DUML commands can also disable or restart the Wi-Fi and Bluetooth interfaces, disconnect Wi-Fi clients, or reset wireless configuration, resulting in a denial-of-service condition that can disrupt the operator's wireless control, video, and telemetry connections during flight. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
DJI Neo 0 ~ 01.00.0400 -
DJI Neo 2 0 ~ 01.00.0500 -
DJI Flip 0 ~ 01.00.1200 -
DJI Air 3 0 ~ 01.00.1600 -
DJI Air 3S 0 ~ 01.00.1400 -
DJI Avata 2 0 ~ 01.00.0400 -
DJI Avata 360 0 ~ 01.00.0300 -
DJI Mavic 3 0 ~ 01.00.1400 -
DJI Mavic 3 Classic 0 ~ 01.00.0800 -
DJI Mavic 3 Pro 0 ~ 01.01.0700 -
DJI Mavic 4 Pro 0 ~ 01.00.0500 -
DJI Mini 2 0 ~ 01.07.0200 -
DJI Mini 3 0 ~ 01.00.0500 -
DJI Mini 3 Pro 0 ~ 01.00.0900 -
DJI Mini 4 Pro 0 ~ 01.00.1100 -
DJI Mini 5 Pro 0 ~ 01.00.0600 -

II. Public POCs for CVE-2026-78306

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78306

登录查看更多情报信息。

Vendor Pages for CVE-2026-78306 (1)

Same Patch Batch · DJI · 2026-08-24 · 4 CVEs total

CVE-2026-78251 9.3 CRITICAL DJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox Directory
CVE-2026-78255 8.7 HIGH DJI Drone HTTP Media Server Allows Unauthenticated Access to Stored Media
CVE-2026-78321 6.0 MEDIUM DJI Drone HTTP Media Server Denial of Service via Connection Pool Exhaustion

IV. Related Vulnerabilities

V. Comments for CVE-2026-78306

No comments yet


Leave a comment