Description
The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media file, preventing the server from handling legitimate requests and causing a denial of service that prevents the DJI Fly application from retrieving photos and videos from the aircraft in QuickTransfer mode.

Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600.

Remediation requires a firmware update from the vendor.
Published: 2026-08-24
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The HTTP media server on DJI drones fails to enforce limits on connections or request rates, allowing an attacker to repeatedly request a stored media file and consume all connections in the server’s pool. This exhausts legitimate traffic and prevents the DJI Fly application from retrieving photos and videos via QuickTransfer, resulting in a denial of service. The flaw is a connection‑pool exhaustion weakness (CWE-770).

Affected Systems

The vulnerability affects a range of DJI aircraft with firmware versions below specific thresholds: DJI Neo < 01.00.0400, Neo 2 < 01.00.0500, Flip < 01.00.1200, Air 3 < 01.00.1600, Air 3S < 01.00.1400, Avata 2 < 01.00.0400, Avata 360 < 01.00.0300, Mavic 3 < 01.00.1400, Mavic 3 Classic < 01.00.0800, Mavic 3 Pro < 01.01.0700, Mavic 4 Pro < 01.00.0500, Mini 2 < 01.07.0200, Mini 3 < 01.00.0500, Mini 3 Pro < 01.00.0900, Mini 4 Pro < 01.00.1100, and Mini 5 Pro < 01.00.0600. All listed models must apply the vendor‑issued firmware update to remediate.

Risk and Exploitability

The CVSS score of 6.0 indicates a moderate risk profile. EPSS data is unavailable, and the flaw is not listed in the CISA KEV catalog, suggesting limited known exploitation. Attackers must first gain internal network access to the aircraft—typically by physical proximity or compromising the Wi‑Fi network—to send repeated media requests. Once inside, they can exhaust the connection pool, causing a service disruption, but the bug does not grant code execution or data exfiltration capabilities.

Generated by OpenCVE AI on August 24, 2026 at 11:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued firmware update that limits connection handling on the HTTP media server.
  • Secure the drone’s internal network by enforcing strong Wi‑Fi credentials, isolating the device from public networks, or applying firewall rules to block unauthorized devices.
  • Monitor the media server for abnormal connection patterns or sustained high‑rate requests, and investigate any sustained high‑rate activity.

Generated by OpenCVE AI on August 24, 2026 at 11:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dji
Dji air 3
Dji air 3s
Dji dji Avata 2
Dji dji Avata 360
Dji dji Mavic 3 Classic
Dji dji Mavic 4 Pro
Dji dji Mini 3 Pro
Dji dji Mini 4 Pro
Dji dji Mini 5 Pro
Dji dji Neo
Dji dji Neo 2
Dji flip
Dji mavic 3
Dji mini 2
Dji mini 3
Vendors & Products Dji
Dji air 3
Dji air 3s
Dji dji Avata 2
Dji dji Avata 360
Dji dji Mavic 3 Classic
Dji dji Mavic 4 Pro
Dji dji Mini 3 Pro
Dji dji Mini 4 Pro
Dji dji Mini 5 Pro
Dji dji Neo
Dji dji Neo 2
Dji flip
Dji mavic 3
Dji mini 2
Dji mini 3

Mon, 24 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media file, preventing the server from handling legitimate requests and causing a denial of service that prevents the DJI Fly application from retrieving photos and videos from the aircraft in QuickTransfer mode. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.
Title DJI Drone HTTP Media Server Denial of Service via Connection Pool Exhaustion
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Dji Air 3 Air 3s Dji Avata 2 Dji Avata 360 Dji Mavic 3 Classic Dji Mavic 4 Pro Dji Mini 3 Pro Dji Mini 4 Pro Dji Mini 5 Pro Dji Neo Dji Neo 2 Flip Mavic 3 Mini 2 Mini 3
cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-08-24T12:51:11.340Z

Reserved: 2026-08-24T08:46:02.862Z

Link: CVE-2026-78321

cve-icon Vulnrichment

Updated: 2026-08-24T12:50:36.317Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T09:16:47.423

Modified: 2026-08-26T16:49:18.760

Link: CVE-2026-78321

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:11:35Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling