Impact
The HTTP media server on DJI drones enables users to retrieve stored photos and videos via the /v2 endpoint without any form of authentication. Because filenames use a predictable scheme, an individual who gains network connectivity to the drone’s internal wireless interface can enumerate valid filenames and download media files. The exposed content can reveal sensitive information such as private locations, property, travel history, identifiable individuals, and operational patterns, constituting a confidentiality breach.
Affected Systems
Affected drone models include DJI Neo, Neo 2, Flip, Air 3, Air 3S, Avata 2, Avata 360, Mavic 3, Mavic 3 Classic, Mavic 3 Pro, Mavic 4 Pro, Mini 2, Mini 3, Mini 3 Pro, Mini 4 Pro and Mini 5 Pro, up to the listed firmware versions.
Risk and Exploitability
This vulnerability is rated with a CVSS score of 8.7, indicating high severity. The EPSS score is unavailable, so the exact likelihood of exploitation is unknown, but the flaw has been included in the DJI documentation and is not listed in the CISA KEV catalog. An attacker must first connect to the drone’s local network, which typically requires physical proximity or compromised Wi‑Fi credentials. Once connected, an attacker can enumerate file names and exfiltrate media without any authentication, resulting in a direct compromise of confidential data.
OpenCVE Enrichment