Impact
The vulnerability lies in an FTP service embedded in DJI drones that uses hardcoded credentials shared across multiple models. Authenticated users can upload files of any size and quantity to the /blackbox/upgrade/ directory, overwrite existing files, and the uploads persist across reboots and factory resets. This allows an attacker with access to the drone’s internal network or USB RNDIS interface to exhaust the available storage, preventing the aircraft from writing flight records, logs, telemetry, and even impeding firmware updates.
Affected Systems
Affected DJI models include Neo, Neo 2, Flip, Air 3, Air 3S, Avata 2, Avata 360, Mavic 3, Mavic 3 Classic, Mavic 3 Pro, Mavic 4 Pro, Mini 2, Mini 3, Mini 3 Pro, Mini 4 Pro, and Mini 5 Pro. Vulnerable firmware versions run up to the following: Neo <= 01.00.0400, Neo 2 <= 01.00.0500, Flip <= 01.00.1200, Air 3 <= 01.00.1600, Air 3S <= 01.00.1400, Avata 2 <= 01.00.0400, Avata 360 <= 01.00.0300, Mavic 3 <= 01.00.1400, Mavic 3 Classic <= 01.00.0800, Mavic 3 Pro <= 01.01.0700, Mavic 4 Pro <= 01.00.0500, Mini 2 <= 01.07.0200, Mini 3 <= 01.00.0500, Mini 3 Pro <= 01.00.0900, Mini 4 Pro <= 01.00.1100, Mini 5 Pro <= 01.00.0600.
Risk and Exploitability
With a CVSS score of 9.3 the risk is high; the EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is at the internal network or USB RNDIS interface, where an authenticated user can exploit hardcoded credentials to upload files. Once the storage is exhausted, critical flight data cannot be recorded and firmware updates may be blocked, effectively causing a denial of service for the drone operations.
OpenCVE Enrichment