Junglewise Threat Intelligence

CVE-2021-44320: Parrot AR.Drone IPv4 flood denial of service

CVE-2021-44320 · Severity: high · CVSS 7.5 · Published 2026-09-04

Executive brief

Parrot AR.Drone quadcopters (versions 1 and 2) lack protection against network-based denial-of-service attacks. An attacker within Wi-Fi range can flood the drone's network interface with SYN or UDP packets, disrupting video streaming, telemetry, and remote control functionality. This renders the device unusable until the attack stops.

Technical details

Parrot AR.Drone versions 1 and 2 lack rate-limiting and traffic filtering mechanisms on their network stack, enabling IPv4 flood-based denial-of-service attacks. An attacker within Wi-Fi range of the drone can connect to its open access point and saturate the network interface with SYN floods, UDP floods, or similar high-volume traffic. This exhausts the onboard computational and memory resources, degrading or completely interrupting telemetry, command, and video-streaming traffic between the drone and its controller. The vulnerability requires adjacent network access (Wi-Fi proximity) but no authentication or user interaction. No patch has been publicly released for these legacy devices.

Affected products

  • Parrot AR.Drone 1 version 1
  • Parrot AR.Drone 2 version 2

Timeline

  • 2021: disclosed: Vulnerability class classification published
  • 2022-03-18: advisory: CVE assigned by MITRE
  • 2026-09-04: other: NVD entry published

References

Related threats