Impact
DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi‑Fi configuration parameters, including SSID, PSK, MAC address, regulatory country code, and wireless channel. By overwriting the Wi‑Fi PSK with a known value, an attacker can connect to the drone's internal Wi‑Fi network, potentially gain access to the flight control interface and issue flight commands. Crafted DUML commands can also disable or restart the Wi‑Fi and Bluetooth interfaces, disconnect Wi‑Fi clients, or reset wireless configuration, producing a denial‑of‑service condition that disrupts the operator's wireless control, video, and telemetry connections during flight.
Affected Systems
The affected models are DJI Neo (firmware up to 01.00.0400), DJI Neo 2 (up to 01.00.0500), DJI Flip (up to 01.00.1200), DJI Air 3 (up to 01.00.1600), DJI Air 3S (up to 01.00.1400), DJI Avata 2 (up to 01.00.0400), DJI Avata 360 (up to 01.00.0300), DJI Mavic 3 (up to 01.00.1400), DJI Mavic 3 Classic (up to 01.00.0800), DJI Mavic 3 Pro (up to 01.01.0700), DJI Mavic 4 Pro (up to 01.00.0500), DJI Mini 2 (up to 01.07.0200), DJI Mini 3 (up to 01.00.0500), DJI Mini 3 Pro (up to 01.00.0900), DJI Mini 4 Pro (up to 01.00.1100), and DJI Mini 5 Pro (up to 01.00.0600).
Risk and Exploitability
The CVSS score of 8.5 indicates a high‑severity vulnerability. Exploitation is not covered by the EPSS metric and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication on the Bluetooth interface allows local attackers within typical Bluetooth range to send malicious DUML commands. The attacker must be physically close, usually within ten meters, but no user interaction or special privilege is required. The potential impact includes unauthorized control of flight operations and disruptions to control, video, and telemetry systems.
OpenCVE Enrichment