Impact
An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, and Mini SE models with firmware version 0.1.00.0500 or earlier permits a remote attacker to trigger a denial of service through the DJI Enhanced‑WiFi transmission subsystem. The weakness is identified as uncontrolled resource consumption (CWE-400), which can cause the drone’s software to become unresponsive or reset.
Affected Systems
Affected DJI hardware includes the Mavic Mini, Spark, Mavic Air, Mini, and Mini SE drones running firmware 0.1.00.0500 or earlier. These models are impacted by the defect in the Enhanced‑WiFi transmission subsystem.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via the wireless interface, as implied by the description of a remote attacker triggering the flaw.
OpenCVE Enrichment