Impact
Parrot AR.Drone 1 and 2 are susceptible to a Wi‑Fi deauthentication attack that allows a remote, unauthenticated adversary to force the drone to disconnect from its controller during flight, resulting in a denial of service. The flaw stems from the lack of authentication checks for deauthentication frames, which can be injected by an attacker within wireless range.
Affected Systems
Parrot AR.Drone 1 and Parrot AR.Drone 2, any firmware version that has not incorporated the vendor’s fix.
Risk and Exploitability
The vulnerability is exploitable without any credentials and requires only a rogue Wi‑Fi client capable of sending deauthentication frames. Because the EPSS score is not available, the current exploitation probability cannot be quantified, and the asset is not listed in the CISA KEV catalog. Nevertheless, the potential impact is high for operational safety, as the drone can lose control mid‑flight. The CVSS score is unspecified, but the attack vector is clearly network‑based and could be performed from a distance equal to the drone’s wireless range.
OpenCVE Enrichment