Description
Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight.
Published: 2026-09-04
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Remote)
Action: Patch Immediately
AI Analysis

Impact

Parrot AR.Drone 1 and AR.Drone 2 are susceptible to a Wi‑Fi deauthentication attack that lets an unauthenticated attacker disconnect the drone from its controller during flight. The flaw is caused by a lack of authentication checks for deauthentication frames, so any rogue Wi‑Fi client can inject such frames. This results in the drone losing control or stalling mid‑flight, directly compromising operational safety.

Affected Systems

Parrot AR.Drone 1 and Parrot AR.Drone 2, any firmware version that has not incorporated the vendor’s fix.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. Because the EPSS score is <1%, exploitation probability is very low and the asset is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker requires no credentials and only a rogue Wi‑Fi client within the drone’s wireless range to perform the attack. The attack vector is network‑based and can be executed from a distance that matches the drone’s wireless coverage. The potential impact is significant for safety, as the drone can lose control mid‑flight.

Generated by OpenCVE AI on September 10, 2026 at 04:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any firmware update or patch from Parrot that addresses the Wi‑Fi deauthentication flaw if one has been released
  • Operate the drone only on a secure, authenticated Wi‑Fi network (e.g., WPA2‑Personal or WPA3) and avoid using open or unencrypted channels
  • Maintain physical proximity between controller and drone; if possible, use a wired or Bluetooth control channel to reduce exposure to deauthentication attacks
  • Monitor flight logs and network traffic for unexpected deauthentication frames and investigate any anomalous activity

Generated by OpenCVE AI on September 10, 2026 at 04:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Remote Wi‑Fi Deauthentication Denial of Service on Parrot AR.Drone
Weaknesses CWE-503

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Parrot
Parrot ar.drone
Vendors & Products Parrot
Parrot ar.drone

Fri, 04 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote Wi‑Fi Deauthentication Denial of Service on Parrot AR.Drone
Weaknesses CWE-503

Fri, 04 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-08T14:16:57.800Z

Reserved: 2021-11-29T00:00:00.000Z

Link: CVE-2021-44319

cve-icon Vulnrichment

Updated: 2026-09-08T14:15:15.613Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T18:17:43.917

Modified: 2026-09-09T16:04:24.933

Link: CVE-2021-44319

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T04:15:14Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption