Junglewise Threat Intelligence

CVE-2026-78306: DJI drones Bluetooth unauthenticated DUML command injection

CVE-2026-78306 · Severity: info · CVSS 8.1 · Published 2026-08-24

Technologies: DJI Neo, DJI Mini 2, DJI Mini 3, DJI Avata 2, DJI Mavic 3, DJI Mini 5 Pro, DJI Mavic 3 Pro, DJI Neo 2, DJI Flip, DJI Air 3, DJI Mini 3 Pro, DJI Mavic 3 Classic, DJI Air 3S, DJI Mavic 4 Pro, DJI Mini 4 Pro, DJI Avata 360. Vendors: DJI.

Executive brief

DJI consumer drones expose an unauthenticated Bluetooth interface that allows an attacker within wireless range to modify the drone's Wi-Fi settings, including network credentials and wireless channels. An attacker can hijack the drone's control network, take over flight operations, or deliberately disrupt the operator's connection to the aircraft during flight, creating a safety hazard.

Technical details

The vulnerability is an unauthenticated command injection in the DUML (DJI Universal Motorcycle Language) protocol over Bluetooth. The Bluetooth interface accepts crafted DUML commands without authentication, allowing an adjacent attacker to modify Wi-Fi SSID, PSK, MAC address, regulatory country, and channel settings. An attacker can overwrite the Wi-Fi pre-shared key with a known value to join the drone's internal control network and issue flight commands, or send crafted commands to disable/restart wireless interfaces, causing denial of service. Remediation requires firmware updates, which are available from DJI for affected models.

Affected products

  • DJI Neo before 01.00.0400
  • DJI Neo 2 before 01.00.0500
  • DJI Flip before 01.00.1200
  • DJI Air 3 before 01.00.1600
  • DJI Air 3S before 01.00.1400
  • DJI Avata 2 before 01.00.0400
  • DJI Avata 360 before 01.00.0300
  • DJI Mavic 3 before 01.00.1400
  • DJI Mavic 3 Classic before 01.00.0800
  • DJI Mavic 3 Pro before 01.01.0700
  • DJI Mavic 4 Pro before 01.00.0500
  • DJI Mini 2 before 01.07.0200
  • DJI Mini 3 before 01.00.0500
  • DJI Mini 3 Pro before 01.00.0900
  • DJI Mini 4 Pro before 01.00.1100
  • DJI Mini 5 Pro before 01.00.0600

Timeline

  • 2026-08-24: disclosed

References

Related threats