Junglewise Threat Intelligence

CVE-2026-77812: DJI drones unencrypted DUML protocol messages over Bluetooth LE

CVE-2026-77812 · Severity: info · Published 2026-08-21

Technologies: DJI Mini 4 Pro, DJI Air 3S, DJI Mini 3, DJI Neo 2, DJI Mavic 3, DJI Mini 5 Pro, DJI Mini 3 Pro, DJI Flip, DJI Mini 2, DJI Avata 2, DJI Mavic 4 Pro, DJI Air 3, DJI Neo, DJI Mavic 3 Pro, DJI Mavic 3 Classic, DJI Avata 360. Vendors: DJI.

Executive brief

DJI drones transmit unencrypted configuration and credentials over Bluetooth, allowing attackers within wireless range to passively intercept Wi-Fi network credentials and session identifiers. An attacker with this information can join the drone's internal network, control services, and decrypt user communications without any indication of the breach.

Technical details

DJI drones exchange DUML (DJI Universal Markup Language) protocol messages over Bluetooth Low Energy without encryption, exposing Wi-Fi SSID, pre-shared keys (PSK), and session UUID identifiers in cleartext. The attack is fully passive—requiring only a BLE sniffer and presence during a normal DJI Fly connection—leaving no trace of compromise. The session UUID is the sole authentication mechanism the drone uses to distinguish trusted clients, so an attacker can replay the captured value to bypass device confirmation. Since credentials persist across sessions unless manually reset, a single passive capture provides indefinite network access. Remediation requires firmware updates; no user-side workaround is available without upgrading.

Affected products

  • DJI Neo before 01.00.0400
  • DJI Neo 2 before 01.00.0500
  • DJI Flip before 01.00.1200
  • DJI Air 3 before 01.00.1600
  • DJI Air 3S before 01.00.1400
  • DJI Avata 2 before 01.00.0400
  • DJI Avata 360 before 01.00.0300
  • DJI Mavic 3 before 01.00.1400
  • DJI Mavic 3 Classic before 01.00.0800
  • DJI Mavic 3 Pro before 01.01.0700
  • DJI Mavic 4 Pro before 01.00.0500
  • DJI Mini 2 before 01.07.0200
  • DJI Mini 3 before 01.00.0500
  • DJI Mini 3 Pro before 01.00.0900
  • DJI Mini 4 Pro before 01.00.1100
  • DJI Mini 5 Pro before 01.00.0600

Timeline

  • 2026-08-21: disclosed

Related threats