Description
DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect to the drone's internal Wi-Fi network, potentially gaining access to the flight control interface and issuing flight commands. Crafted DUML commands can also disable or restart the Wi-Fi and Bluetooth interfaces, disconnect Wi-Fi clients, or reset wireless configuration, resulting in a denial-of-service condition that can disrupt the operator's wireless control, video, and telemetry connections during flight.

Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600.


Remediation requires a firmware update from the vendor.
Published: 2026-08-24
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized flight control manipulation
Action: Immediate Patch
AI Analysis

Impact

DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi‑Fi configuration parameters, including SSID, PSK, MAC address, regulatory country code, and wireless channel. By overwriting the Wi‑Fi PSK with a known value, an attacker can connect to the drone's internal Wi‑Fi network, potentially gain access to the flight control interface and issue flight commands. Crafted DUML commands can also disable or restart the Wi‑Fi and Bluetooth interfaces, disconnect Wi‑Fi clients, or reset wireless configuration, producing a denial‑of‑service condition that disrupts the operator's wireless control, video, and telemetry connections during flight.

Affected Systems

The affected models are DJI Neo (firmware up to 01.00.0400), DJI Neo 2 (up to 01.00.0500), DJI Flip (up to 01.00.1200), DJI Air 3 (up to 01.00.1600), DJI Air 3S (up to 01.00.1400), DJI Avata 2 (up to 01.00.0400), DJI Avata 360 (up to 01.00.0300), DJI Mavic 3 (up to 01.00.1400), DJI Mavic 3 Classic (up to 01.00.0800), DJI Mavic 3 Pro (up to 01.01.0700), DJI Mavic 4 Pro (up to 01.00.0500), DJI Mini 2 (up to 01.07.0200), DJI Mini 3 (up to 01.00.0500), DJI Mini 3 Pro (up to 01.00.0900), DJI Mini 4 Pro (up to 01.00.1100), and DJI Mini 5 Pro (up to 01.00.0600).

Risk and Exploitability

The CVSS score of 8.5 indicates a high‑severity vulnerability. Exploitation is not covered by the EPSS metric and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication on the Bluetooth interface allows local attackers within typical Bluetooth range to send malicious DUML commands. The attacker must be physically close, usually within ten meters, but no user interaction or special privilege is required. The potential impact includes unauthorized control of flight operations and disruptions to control, video, and telemetry systems.

Generated by OpenCVE AI on August 24, 2026 at 09:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a firmware update from DJI that removes the unauthenticated DUML interface.
  • Disable Bluetooth connectivity on the drone when it is not actively being used for remote control or monitoring.
  • Change the Wi‑Fi PSK to a strong unique value and avoid using default or easily guessable passwords to reduce the risk of an attacker gaining access to the internal network.

Generated by OpenCVE AI on August 24, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dji
Dji air 3
Dji air 3s
Dji dji Avata 2
Dji dji Avata 360
Dji dji Mavic 3 Classic
Dji dji Mavic 4 Pro
Dji dji Mini 3 Pro
Dji dji Mini 4 Pro
Dji dji Mini 5 Pro
Dji dji Neo
Dji dji Neo 2
Dji flip
Dji mavic 3
Dji mini 2
Dji mini 3
Vendors & Products Dji
Dji air 3
Dji air 3s
Dji dji Avata 2
Dji dji Avata 360
Dji dji Mavic 3 Classic
Dji dji Mavic 4 Pro
Dji dji Mini 3 Pro
Dji dji Mini 4 Pro
Dji dji Mini 5 Pro
Dji dji Neo
Dji dji Neo 2
Dji flip
Dji mavic 3
Dji mini 2
Dji mini 3

Mon, 24 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect to the drone's internal Wi-Fi network, potentially gaining access to the flight control interface and issuing flight commands. Crafted DUML commands can also disable or restart the Wi-Fi and Bluetooth interfaces, disconnect Wi-Fi clients, or reset wireless configuration, resulting in a denial-of-service condition that can disrupt the operator's wireless control, video, and telemetry connections during flight. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.
Title DJI Drone Bluetooth Interface Unauthenticated DUML Command Execution
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}


Subscriptions

Dji Air 3 Air 3s Dji Avata 2 Dji Avata 360 Dji Mavic 3 Classic Dji Mavic 4 Pro Dji Mini 3 Pro Dji Mini 4 Pro Dji Mini 5 Pro Dji Neo Dji Neo 2 Flip Mavic 3 Mini 2 Mini 3
cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-08-24T12:51:11.501Z

Reserved: 2026-08-24T08:07:50.044Z

Link: CVE-2026-78306

cve-icon Vulnrichment

Updated: 2026-08-24T12:50:42.464Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T09:16:47.200

Modified: 2026-08-26T16:49:18.760

Link: CVE-2026-78306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:11:37Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function