Executive brief
DJI drone models contain an FTP service with hardcoded credentials that allows attackers to upload unlimited files to critical storage directories. An attacker with network access to the drone can fill storage with malicious files, preventing the aircraft from recording flight logs, telemetry, and firmware updates, which could disable safety features and strand the device.
Technical details
The vulnerability is a hardcoded credential and unrestricted file upload issue in the FTP service present on multiple DJI drone models. Attackers who gain access to the drone's internal network or USB RNDIS interface can use static credentials to authenticate to the FTP service and upload files of any size to the /blackbox/upgrade/ directory without restrictions on file count or total storage consumption. The attack allows overwriting existing files and persists across reboot and factory reset, enabling denial-of-service attacks that prevent flight logging, telemetry recording, and firmware updates. Vendor remediation requires a firmware update to all affected models.
Affected products
- DJI Neo before 01.00.0400
- DJI Neo 2 before 01.00.0500
- DJI Flip before 01.00.1200
- DJI Air 3 before 01.00.1600
- DJI Air 3S before 01.00.1400
- DJI Avata 2 before 01.00.0400
- DJI Avata 360 before 01.00.0300
- DJI Mavic 3 before 01.00.1400
- DJI Mavic 3 Classic before 01.00.0800
- DJI Mavic 3 Pro before 01.01.0700
- DJI Mavic 4 Pro before 01.00.0500
- DJI Mini 2 before 01.07.0200
- DJI Mini 3 before 01.00.0500
- DJI Mini 3 Pro before 01.00.0900
- DJI Mini 4 Pro before 01.00.1100
- DJI Mini 5 Pro before 01.00.0600
Timeline
- 2026-08-27: disclosed