Junglewise Threat Intelligence

CVE-2026-78255: DJI drones HTTP media server unauthenticated photo and video access

CVE-2026-78255 · Severity: info · Published 2026-08-24

Technologies: DJI Neo, DJI Mini 2, DJI Mini 3, DJI Avata 2, DJI Mavic 3, DJI Mini 5 Pro, DJI Mavic 3 Pro, DJI Neo 2, DJI Flip, DJI Air 3, DJI Mini 3 Pro, DJI Mavic 3 Classic, DJI Air 3S, DJI Mavic 4 Pro, DJI Mini 4 Pro, DJI Avata 360. Vendors: DJI.

Executive brief

DJI drones expose an HTTP media server that serves stored photos and videos through the `/v2` endpoint without requiring authentication. An attacker with access to the drone's internal network can enumerate and download all stored media, which may contain sensitive information such as private locations, property details, travel history, identifiable individuals, and operator routines. This exposure poses significant privacy and security risks to drone operators and anyone photographed or filmed.

Technical details

The vulnerability is an authentication bypass in the HTTP media server component of multiple DJI drone models. The `/v2` endpoint fails to validate the requesting client's credentials or authorization before serving photos and videos. Attack precondition: an attacker must gain access to the drone's internal network (via WiFi proximity). The predictable filename pattern allows trivial enumeration of valid media files. An attacker can exfiltrate all stored media without authentication or user interaction. Patches are available through firmware updates to affected models.

Affected products

  • DJI Neo before 01.00.0400
  • DJI Neo 2 before 01.00.0500
  • DJI Flip before 01.00.1200
  • DJI Air 3 before 01.00.1600
  • DJI Air 3S before 01.00.1400
  • DJI Avata 2 before 01.00.0400
  • DJI Avata 360 before 01.00.0300
  • DJI Mavic 3 before 01.00.1400
  • DJI Mavic 3 Classic before 01.00.0800
  • DJI Mavic 3 Pro before 01.01.0700
  • DJI Mavic 4 Pro before 01.00.0500
  • DJI Mini 2 before 01.07.0200
  • DJI Mini 3 before 01.00.0500
  • DJI Mini 3 Pro before 01.00.0900
  • DJI Mini 4 Pro before 01.00.1100
  • DJI Mini 5 Pro before 01.00.0600

Timeline

  • 2026-08-24: disclosed

References

Related threats