Impact
DJI drones broadcast Wi‑Fi credentials in cleartext over Bluetooth Low Energy using the DUML protocol, exposing the SSID, PSK, and a trusted session UUID. An attacker in BLE range can silently capture these messages, obtain the credentials, and join the drone’s internal Wi‑Fi network without needing to authenticate or trigger any user interface. Once connected, the attacker can interact with network services, intercept or decrypt communications between the drone and the operator, and bypass subsequent physical confirmation checks. This flaw is a classic information disclosure vulnerability (CWE‑311).
Affected Systems
Affected models include DJI Air 3, Air 3S, Avata 2, Avata 360, Flip, Mavic 3, Mavic 3 Classic, Mavic 3 Pro, Mavic 4 Pro, Mini 2, Mini 3, Mini 3 Pro, Mini 4 Pro, Mini 5 Pro, Neo, and Neo 2, all with firmware versions prior to the respective dates listed in the advisory (e.g., Air 3 through 01.00.1600, Mini 5 Pro through 01.00.0600).
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity, and the exploit is fully passive: no traffic is transmitted back to the drone, and neither the operator nor the drone detects that the session was observed. Only a BLE sniffer and proximity to the drone during a normal DJI Fly connection are required, and the captured credentials remain valid until the operator manually resets the Wi‑Fi settings, giving an attacker indefinite reuse potential. The EPSS score is unavailable, and the vulnerability is not yet listed in CISA’s KEV catalog, but the high CVSS and the ease of capture make it a high‑risk exposure for any deployed DJI drones.
OpenCVE Enrichment