Junglewise Threat Intelligence

CVE-2026-78321: DJI drone HTTP media server denial of service via connection exhaustion

CVE-2026-78321 · Severity: info · Published 2026-08-24

Technologies: DJI Neo, DJI Mini 2, DJI Mini 3, DJI Avata 2, DJI Mavic 3, DJI Mini 5 Pro, DJI Mavic 3 Pro, DJI Neo 2, DJI Flip, DJI Air 3, DJI Mini 3 Pro, DJI Mavic 3 Classic, DJI Air 3S, DJI Mavic 4 Pro, DJI Mini 4 Pro, DJI Avata 360. Vendors: DJI.

Executive brief

DJI drones include an HTTP media server that transfers photos and videos to the DJI Fly mobile app. The server lacks rate limiting on incoming connections, allowing an attacker on the drone's network to flood it with requests and crash the service, preventing users from retrieving their media files and interrupting normal operations.

Technical details

The vulnerability is a denial of service (DoS) condition in the HTTP media server component of DJI drone firmware caused by insufficient connection and request rate limits. An attacker with network access to the drone can exhaust the server's connection pool by repeatedly requesting stored media files, causing the server to drop legitimate requests from the DJI Fly application. The attack requires local network access (adjacent network vector) and impacts the QuickTransfer media retrieval mode. Patches are available via firmware updates for all affected models.

Affected products

  • DJI Neo before 01.00.0400
  • DJI Neo 2 before 01.00.0500
  • DJI Flip before 01.00.1200
  • DJI Air 3 before 01.00.1600
  • DJI Air 3S before 01.00.1400
  • DJI Avata 2 before 01.00.0400
  • DJI Avata 360 before 01.00.0300
  • DJI Mavic 3 before 01.00.1400
  • DJI Mavic 3 Classic before 01.00.0800
  • DJI Mavic 3 Pro before 01.01.0700
  • DJI Mavic 4 Pro before 01.00.0500
  • DJI Mini 2 before 01.07.0200
  • DJI Mini 3 before 01.00.0500
  • DJI Mini 3 Pro before 01.00.0900
  • DJI Mini 4 Pro before 01.00.1100
  • DJI Mini 5 Pro before 01.00.0600

Timeline

  • 2026-08-24: disclosed

References

Related threats