CVE-2026-78255
8.7DJI · Neo, Neo 2, Flip, Air 3, Air 3S, Avata 2
The HTTP media server in multiple DJI drone models lacks authentication, allowing unauthenticated attackers to access stored photos and videos via the /v2 endpoint.
Executive summary
A critical authentication bypass in the DJI drone media server allows unauthorized access to sensitive media files by unauthenticated network attackers.
Vulnerability
This is a missing authentication vulnerability (CWE-306) affecting the HTTP media server. An unauthenticated attacker can query the /v2 endpoint to retrieve sensitive media content stored on the device.
Business impact
Successful exploitation poses a significant risk to data privacy and operational security. Unauthorized access to drone media could lead to the exposure of sensitive imagery, proprietary data, or reconnaissance material, causing potential reputational damage. With a CVSS score of 8.7, this is a high-severity risk that requires immediate attention to protect captured data.
Remediation
Immediate Action: Update all affected drone firmware to the latest available version provided by the manufacturer.
Proactive Monitoring: Monitor network traffic to drone devices for unusual HTTP GET requests directed at the /v2 path.
Compensating Controls: Ensure drone devices are operated within secure, private network segments where unauthorized network access is strictly restricted.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the high CVSS score and the sensitive nature of the data stored on these devices, organizations should prioritize firmware updates. Ensure that all drone units are patched to the latest version to close this unauthenticated access vector immediately.