CVE-2026-26673

7.5

DJI · Mavic Mini, Spark, Mavic Air, Mini SE

A vulnerability in the DJI Enhanced-WiFi transmission subsystem allows remote, unauthenticated attackers to trigger a denial of service condition on multiple drone models.

Executive summary

A critical vulnerability in DJI drone models allows unauthenticated remote attackers to cause a denial of service via the WiFi transmission subsystem, posing a significant operational risk.

Vulnerability

The vulnerability exists within the DJI Enhanced-WiFi transmission subsystem and allows an unauthenticated remote attacker to disrupt system availability. The flaw is remotely exploitable without user interaction or prior authentication.

Business impact

The exploitation of this vulnerability results in a denial of service, which would render the affected drone hardware unresponsive during operation. Given the nature of drone deployments, this could lead to total loss of equipment, disruption of mission-critical aerial tasks, or safety hazards. With a CVSS score of 7.5, this high-severity flaw necessitates immediate attention to ensure operational continuity and safety.

Remediation

Immediate Action: Consult the official DJI security portal for firmware updates addressing the Enhanced-WiFi subsystem and apply them to all affected drone units as soon as they become available.

Proactive Monitoring: Monitor drone control links for unusual latency, signal drops, or unexpected disconnections that may indicate attempts to interfere with the transmission subsystem.

Compensating Controls: Ensure that drone operations are conducted in secure or controlled radio frequency environments to minimize exposure to unauthorized remote WiFi signals.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available in the provided data.

Analyst recommendation

This vulnerability presents a clear risk to the availability of affected DJI hardware. Organizations should prioritize updating drone firmware to version 0.1.00.0500 or higher once the vendor releases a patch, as the current inability to patch makes these devices inherently vulnerable to remote disruption. Immediate verification of current firmware versions across all fleet units is strongly advised.

More DJI CVEs

Sources