CVE-2026-78306
8.5DJI · Neo, Neo 2, Flip, Air 3, Air 3S, Avata 2
DJI drones expose an unauthenticated Bluetooth DUML interface, allowing attackers within range to modify critical Wi-Fi and network configuration parameters.
Executive summary
An unauthenticated command interface in DJI drones allows attackers to modify critical wireless network configurations via Bluetooth, risking device hijacking.
Vulnerability
This is a missing authentication for a critical function (CWE-306) affecting the DUML command interface over Bluetooth. An unauthenticated attacker in physical proximity can change wireless settings, including SSID and PSK, potentially leading to a man-in-the-middle attack or device disconnection.
Business impact
Exploitation of this vulnerability allows an attacker to disrupt drone operations or redirect the device to a malicious network. This poses a high risk to operational continuity and could result in the total loss of control over the drone. The CVSS score of 8.5 underscores the critical nature of this flaw.
Remediation
Immediate Action: Update the drone firmware to the latest version provided by the manufacturer.
Proactive Monitoring: Monitor for unexpected Bluetooth connection attempts or unauthorized changes to Wi-Fi settings in the device logs.
Compensating Controls: Keep drones stored in secure locations and disable Bluetooth connectivity when the drone is not in active use, if the device settings allow.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Organizations should prioritize the deployment of firmware updates for all affected DJI drone models. Given the potential for total device configuration modification, patching is essential to prevent unauthorized wireless manipulation.