Description
DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset.

Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600.

Remediation requires a firmware update from the vendor.
Published: 2026-08-24
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in an FTP service embedded in DJI drones that uses hardcoded credentials shared across multiple models. Authenticated users can upload files of any size and quantity to the /blackbox/upgrade/ directory, overwrite existing files, and the uploads persist across reboots and factory resets. This allows an attacker with access to the drone’s internal network or USB RNDIS interface to exhaust the available storage, preventing the aircraft from writing flight records, logs, telemetry, and even impeding firmware updates.

Affected Systems

Affected DJI models include Neo, Neo 2, Flip, Air 3, Air 3S, Avata 2, Avata 360, Mavic 3, Mavic 3 Classic, Mavic 3 Pro, Mavic 4 Pro, Mini 2, Mini 3, Mini 3 Pro, Mini 4 Pro, and Mini 5 Pro. Vulnerable firmware versions run up to the following: Neo <= 01.00.0400, Neo 2 <= 01.00.0500, Flip <= 01.00.1200, Air 3 <= 01.00.1600, Air 3S <= 01.00.1400, Avata 2 <= 01.00.0400, Avata 360 <= 01.00.0300, Mavic 3 <= 01.00.1400, Mavic 3 Classic <= 01.00.0800, Mavic 3 Pro <= 01.01.0700, Mavic 4 Pro <= 01.00.0500, Mini 2 <= 01.07.0200, Mini 3 <= 01.00.0500, Mini 3 Pro <= 01.00.0900, Mini 4 Pro <= 01.00.1100, Mini 5 Pro <= 01.00.0600.

Risk and Exploitability

With a CVSS score of 9.3 the risk is high; the EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is at the internal network or USB RNDIS interface, where an authenticated user can exploit hardcoded credentials to upload files. Once the storage is exhausted, critical flight data cannot be recorded and firmware updates may be blocked, effectively causing a denial of service for the drone operations.

Generated by OpenCVE AI on August 24, 2026 at 08:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by DJI that removes or limits the unrestricted upload capability to the /blackbox/upgrade/ directory.
  • Disable or block the FTP service on the drone, for example by configuring network firewall rules or removing the FTP port from the internal network if remote access is unnecessary.
  • Monitor the free space of the /blackbox/upgrade/ directory and set alerts to detect when storage approaches capacity to intervene before logs or updates fail.

Generated by OpenCVE AI on August 24, 2026 at 08:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https:// cve-icon
History

Mon, 24 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.
Title DJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox Directory
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-08-24T07:04:32.474Z

Reserved: 2026-08-24T07:02:39.767Z

Link: CVE-2026-78251

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T08:30:14Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials