CVE-2026-78251

9.3

DJI · Neo

DJI drones contain an FTP service with hardcoded credentials that allows unauthorized file uploads and storage exhaustion, potentially disabling critical flight logging and firmware update capabilities.

Executive summary

Multiple DJI drone models are affected by a critical vulnerability involving hardcoded credentials in the FTP service, allowing attackers to disrupt device functionality and persistence.

Vulnerability

The vulnerability stems from the use of hardcoded credentials within the drone FTP service. This allows an unauthenticated attacker, with access to the local network or USB RNDIS interface, to upload arbitrary files, overwrite system files, and cause storage exhaustion that persists across device reboots and resets.

Business impact

Exploitation of this vulnerability poses a significant risk to the operational reliability of the drones. By exhausting storage, an attacker can prevent the recording of flight telemetry and logs, which may be required for regulatory compliance or incident investigation. With a CVSS score of 9.3, the potential for persistent system disruption is extremely high and could lead to total loss of device control or inability to perform safety-critical firmware updates.

Remediation

Immediate Action: Apply the latest firmware updates provided by DJI for the specific drone model immediately.

Proactive Monitoring: Restrict access to the drone's network interfaces and monitor for any unauthorized connections to the FTP service.

Compensating Controls: If firmware updates cannot be applied immediately, ensure the drone is not exposed to untrusted networks or physical access interfaces that could allow unauthorized FTP connections.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the critical nature of this vulnerability and the potential for persistent impact on device operation, users must verify their drone model firmware versions against the vendor list and apply updates without delay.

More DJI CVEs