Impact
The HTTP media server on DJI drones fails to enforce limits on connections or request rates, allowing an attacker to repeatedly request a stored media file and consume all connections in the server’s pool. This exhausts legitimate traffic and prevents the DJI Fly application from retrieving photos and videos via QuickTransfer, resulting in a denial of service. The flaw is a connection‑pool exhaustion weakness (CWE-770).
Affected Systems
The vulnerability affects a range of DJI aircraft with firmware versions below specific thresholds: DJI Neo < 01.00.0400, Neo 2 < 01.00.0500, Flip < 01.00.1200, Air 3 < 01.00.1600, Air 3S < 01.00.1400, Avata 2 < 01.00.0400, Avata 360 < 01.00.0300, Mavic 3 < 01.00.1400, Mavic 3 Classic < 01.00.0800, Mavic 3 Pro < 01.01.0700, Mavic 4 Pro < 01.00.0500, Mini 2 < 01.07.0200, Mini 3 < 01.00.0500, Mini 3 Pro < 01.00.0900, Mini 4 Pro < 01.00.1100, and Mini 5 Pro < 01.00.0600. All listed models must apply the vendor‑issued firmware update to remediate.
Risk and Exploitability
The CVSS score of 6.0 indicates a moderate risk profile. EPSS data is unavailable, and the flaw is not listed in the CISA KEV catalog, suggesting limited known exploitation. Attackers must first gain internal network access to the aircraft—typically by physical proximity or compromising the Wi‑Fi network—to send repeated media requests. Once inside, they can exhaust the connection pool, causing a service disruption, but the bug does not grant code execution or data exfiltration capabilities.
OpenCVE Enrichment