Impact
Parrot AR.Drone 1 and AR.Drone 2 are susceptible to a Wi‑Fi deauthentication attack that lets an unauthenticated attacker disconnect the drone from its controller during flight. The flaw is caused by a lack of authentication checks for deauthentication frames, so any rogue Wi‑Fi client can inject such frames. This results in the drone losing control or stalling mid‑flight, directly compromising operational safety.
Affected Systems
Parrot AR.Drone 1 and Parrot AR.Drone 2, any firmware version that has not incorporated the vendor’s fix.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. Because the EPSS score is <1%, exploitation probability is very low and the asset is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker requires no credentials and only a rogue Wi‑Fi client within the drone’s wireless range to perform the attack. The attack vector is network‑based and can be executed from a distance that matches the drone’s wireless coverage. The potential impact is significant for safety, as the drone can lose control mid‑flight.
OpenCVE Enrichment