Executive brief
DJI drones transmit unencrypted configuration and credentials over Bluetooth, allowing attackers within wireless range to passively intercept Wi-Fi network credentials and session identifiers. An attacker with this information can join the drone's internal network, control services, and decrypt user communications without any indication of the breach.
Technical details
DJI drones exchange DUML (DJI Universal Markup Language) protocol messages over Bluetooth Low Energy without encryption, exposing Wi-Fi SSID, pre-shared keys (PSK), and session UUID identifiers in cleartext. The attack is fully passive—requiring only a BLE sniffer and presence during a normal DJI Fly connection—leaving no trace of compromise. The session UUID is the sole authentication mechanism the drone uses to distinguish trusted clients, so an attacker can replay the captured value to bypass device confirmation. Since credentials persist across sessions unless manually reset, a single passive capture provides indefinite network access. Remediation requires firmware updates; no user-side workaround is available without upgrading.
Affected products
- DJI Neo before 01.00.0400
- DJI Neo 2 before 01.00.0500
- DJI Flip before 01.00.1200
- DJI Air 3 before 01.00.1600
- DJI Air 3S before 01.00.1400
- DJI Avata 2 before 01.00.0400
- DJI Avata 360 before 01.00.0300
- DJI Mavic 3 before 01.00.1400
- DJI Mavic 3 Classic before 01.00.0800
- DJI Mavic 3 Pro before 01.01.0700
- DJI Mavic 4 Pro before 01.00.0500
- DJI Mini 2 before 01.07.0200
- DJI Mini 3 before 01.00.0500
- DJI Mini 3 Pro before 01.00.0900
- DJI Mini 4 Pro before 01.00.1100
- DJI Mini 5 Pro before 01.00.0600
Timeline
- 2026-08-21: disclosed