CVE-2026-78306
- EPSS 0.15%
- Veröffentlicht 24.08.2026 09:16:47
- Zuletzt bearbeitet 26.08.2026 16:49:18
DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. A...
- EPSS 0.16%
- Veröffentlicht 24.08.2026 09:16:47
- Zuletzt bearbeitet 26.08.2026 16:49:18
The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media ...
CVE-2026-78255
- EPSS 0.24%
- Veröffentlicht 24.08.2026 08:16:33
- Zuletzt bearbeitet 26.08.2026 16:49:18
The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a predictable pattern, allowing an attacker who joins the drone's internal network t...
CVE-2026-78251
- EPSS 0.39%
- Veröffentlicht 24.08.2026 07:04:32
- Zuletzt bearbeitet 28.08.2026 15:28:32
DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as o...
CVE-2026-77812
- EPSS 0.06%
- Veröffentlicht 21.08.2026 15:16:47
- Zuletzt bearbeitet 26.08.2026 16:49:18
DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to QuickTransfer mode, the DJI Fly...
CVE-2023-6951
- EPSS 0.29%
- Veröffentlicht 02.04.2024 11:15:51
- Zuletzt bearbeitet 15.04.2026 00:35:42
A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the WPA2 PSK key and authenticate without permission to the drone’s Wi- Fi network. This, in turn, allows the...
- EPSS 0.21%
- Veröffentlicht 02.04.2024 11:15:50
- Zuletzt bearbeitet 15.04.2026 00:35:42
A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payload triggering a missing input size check in the proc...
CVE-2023-51454
- EPSS 0.25%
- Veröffentlicht 02.04.2024 11:15:50
- Zuletzt bearbeitet 15.04.2026 00:35:42
A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to overwrite a pointer in the process memory through a crafted payload triggering an unsafe memory write operatio...
CVE-2023-51455
- EPSS 0.25%
- Veröffentlicht 02.04.2024 11:15:50
- Zuletzt bearbeitet 15.04.2026 00:35:42
A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to corrupt a controlled memory location due to a missing input validation in the on_receive_sessio...
CVE-2023-51456
- EPSS 0.25%
- Veröffentlicht 02.04.2024 11:15:50
- Zuletzt bearbeitet 15.04.2026 00:35:42
A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to trigger an out-of-bound read/write into the process memory through a crafted payload due to a missing in...