CVE-2026-78306
Last modified
CVE-2026-78306 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect to the drone's internal Wi-Fi network, potentially gaining access to the flight control interface and issuing flight commands.
Description
DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect to the drone's internal Wi-Fi network, potentially gaining access to the flight control interface and issuing flight commands. Crafted DUML commands can also disable or restart the Wi-Fi and Bluetooth interfaces, disconnect Wi-Fi clients, or reset wireless configuration, resulting in a denial-of-service condition that can disrupt the operator's wireless control, video, and telemetry connections during flight. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.
Metrics
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| DJI | Neo | <= 01.00.0400 |
| DJI | Neo 2 | <= 01.00.0500 |
| DJI | Flip | <= 01.00.1200 |
| DJI | Air 3 | <= 01.00.1600 |
| DJI | Air 3S | <= 01.00.1400 |
| DJI | Avata 2 | <= 01.00.0400 |
| DJI | Avata 360 | <= 01.00.0300 |
| DJI | Mavic 3 | <= 01.00.1400 |
| DJI | Mavic 3 Classic | <= 01.00.0800 |
| DJI | Mavic 3 Pro | <= 01.01.0700 |
| DJI | Mavic 4 Pro | <= 01.00.0500 |
| DJI | Mini 2 | <= 01.07.0200 |
| DJI | Mini 3 | <= 01.00.0500 |
| DJI | Mini 3 Pro | <= 01.00.0900 |
| DJI | Mini 4 Pro | <= 01.00.1100 |
| DJI | Mini 5 Pro | <= 01.00.0600 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-78306?
How severe is CVE-2026-78306?
How do I fix CVE-2026-78306?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-78282Unauthenticated Cross Site Scripting (XSS) in Stripe Payment…7.1
- CVE-2026-78284Unauthenticated Arbitrary File Deletion in MasterStudy LMS <…8.6
- CVE-2026-7829UltraVNC repeater through 1.8.2.2 contains a post-authentica…7.2
- CVE-2026-78290Contributor Cross Site Scripting (XSS) in Magazine Blocks <=…6.5
- CVE-2026-78291Unauthenticated Broken Access Control in RepairBuddy <= 4.12…5.3
- CVE-2026-7830UltraVNC through 1.8.2.2 uses inadequate cryptography in the…7.4
- CVE-2026-7831UltraVNC viewer through 1.8.2.2 contains an off-by-one stack…7.6
- CVE-2026-78314SQL Injection in Delta DIAEnergie v1.11.00.002 allows attack…8.8
- CVE-2026-78315SQL Injection in Delta DIAEnergie v1.11.00.002 allows attack…8.8
- CVE-2026-78316SQL Injection in Delta DIAEnergie v1.11.00.002 allows attack…8.8
- CVE-2026-78317SQL Injection in Delta DIAEnergie v1.11.00.002 allows attack…8.8
- CVE-2026-7832A security flaw has been discovered in IObit Advanced System…7
Are you affected by CVE-2026-78306?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
