Description
Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight.
Published: 2026-09-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Parrot AR.Drone 1 and 2 are susceptible to a Wi‑Fi deauthentication attack that allows a remote, unauthenticated adversary to force the drone to disconnect from its controller during flight, resulting in a denial of service. The flaw stems from the lack of authentication checks for deauthentication frames, which can be injected by an attacker within wireless range.

Affected Systems

Parrot AR.Drone 1 and Parrot AR.Drone 2, any firmware version that has not incorporated the vendor’s fix.

Risk and Exploitability

The vulnerability is exploitable without any credentials and requires only a rogue Wi‑Fi client capable of sending deauthentication frames. Because the EPSS score is not available, the current exploitation probability cannot be quantified, and the asset is not listed in the CISA KEV catalog. Nevertheless, the potential impact is high for operational safety, as the drone can lose control mid‑flight. The CVSS score is unspecified, but the attack vector is clearly network‑based and could be performed from a distance equal to the drone’s wireless range.

Generated by OpenCVE AI on September 4, 2026 at 21:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update or patch from Parrot that addresses the Wi‑Fi deauthentication flaw if one is available
  • Restrict the drone’s wireless usage to trusted, authenticated networks and avoid open or non‑secured Wi‑Fi channels during flight
  • Enforce proximity between controller and drone, and if possible use wired or Bluetooth-based control to reduce exposure to deauthentication attacks
  • Monitor flight operations for unexpected disconnects and investigate any anomalous wireless traffic

Generated by OpenCVE AI on September 4, 2026 at 21:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote Wi‑Fi Deauthentication Denial of Service on Parrot AR.Drone
Weaknesses CWE-503

Fri, 04 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-04T18:01:52.127Z

Reserved: 2021-11-29T00:00:00.000Z

Link: CVE-2021-44319

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T18:17:43.917

Modified: 2026-09-04T18:17:43.917

Link: CVE-2021-44319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T22:00:06Z

Weaknesses