CVE-2026-78255

8.7

DJI · Neo, Neo 2, Flip, Air 3, Air 3S, Avata 2

The HTTP media server in multiple DJI drone models lacks authentication, allowing unauthenticated attackers to access stored photos and videos via the /v2 endpoint.

Executive summary

A critical authentication bypass in the DJI drone media server allows unauthorized access to sensitive media files by unauthenticated network attackers.

Vulnerability

This is a missing authentication vulnerability (CWE-306) affecting the HTTP media server. An unauthenticated attacker can query the /v2 endpoint to retrieve sensitive media content stored on the device.

Business impact

Successful exploitation poses a significant risk to data privacy and operational security. Unauthorized access to drone media could lead to the exposure of sensitive imagery, proprietary data, or reconnaissance material, causing potential reputational damage. With a CVSS score of 8.7, this is a high-severity risk that requires immediate attention to protect captured data.

Remediation

Immediate Action: Update all affected drone firmware to the latest available version provided by the manufacturer.

Proactive Monitoring: Monitor network traffic to drone devices for unusual HTTP GET requests directed at the /v2 path.

Compensating Controls: Ensure drone devices are operated within secure, private network segments where unauthorized network access is strictly restricted.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the high CVSS score and the sensitive nature of the data stored on these devices, organizations should prioritize firmware updates. Ensure that all drone units are patched to the latest version to close this unauthenticated access vector immediately.

More DJI CVEs