CVE-2026-78321
Last modified
CVE-2026-78321 is a medium-severity vulnerability rated 6/10 on the CVSS scale. The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media file, preventing the server from handling legitimate requests and causing a denial of service that prevents the DJI Fly application from retrieving photos and videos from the aircraft in QuickTransfer mode. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor..
Description
The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media file, preventing the server from handling legitimate requests and causing a denial of service that prevents the DJI Fly application from retrieving photos and videos from the aircraft in QuickTransfer mode. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.
Metrics
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| DJI | Neo | <= 01.00.0400, |
| DJI | Neo 2 | <= 01.00.0500 |
| DJI | Flip | <= 01.00.1200 |
| DJI | Air 3 | <= 01.00.1600 |
| DJI | Air 3S | <= 01.00.1400 |
| DJI | Avata 2 | <= 01.00.0400 |
| DJI | Avata 360 | <= 01.00.0300 |
| DJI | Mavic 3 | <= 01.00.1400 |
| DJI | Mavic 3 Classic | <= 01.00.0800 |
| DJI | Mavic 3 Pro | <= 01.01.0700 |
| DJI | Mavic 4 Pro | <= 01.00.0500 |
| DJI | Mini 2 | <= 01.07.0200, |
| DJI | Mini 3 | <= 01.00.0500 |
| DJI | Mini 3 Pro | <= 01.00.0900 |
| DJI | Mini 4 Pro | <= 01.00.1100 |
| DJI | Mini 5 Pro | <= 01.00.0600 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-78321?
How severe is CVE-2026-78321?
How do I fix CVE-2026-78321?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7831UltraVNC viewer through 1.8.2.2 contains an off-by-one stack…7.6
- CVE-2026-78314SQL Injection in Delta DIAEnergie v1.11.00.002 allows attack…8.8
- CVE-2026-78315SQL Injection in Delta DIAEnergie v1.11.00.002 allows attack…8.8
- CVE-2026-78316SQL Injection in Delta DIAEnergie v1.11.00.002 allows attack…8.8
- CVE-2026-78317SQL Injection in Delta DIAEnergie v1.11.00.002 allows attack…8.8
- CVE-2026-7832A security flaw has been discovered in IObit Advanced System…7
- CVE-2026-78322A flaw was found in file-roller. When opening or extracting …6.5
- CVE-2026-78323A flaw was found in JSS (Java Security Services). The JSSTru…6.5
- CVE-2026-78329Improper input validation vulnerability in Apache Camel Unde…
- CVE-2026-7833A weakness has been identified in EFM ipTIME C200 up to 1.09…7.3
- CVE-2026-78337Unrestricted Upload of File with Dangerous Type in the compa…4.8
- CVE-2026-7834A security vulnerability has been detected in EFM ipTIME NAS…9.8
Are you affected by CVE-2026-78321?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
