Executive brief
DJI drones include an HTTP media server that transfers photos and videos to the DJI Fly mobile app. The server lacks rate limiting on incoming connections, allowing an attacker on the drone's network to flood it with requests and crash the service, preventing users from retrieving their media files and interrupting normal operations.
Technical details
The vulnerability is a denial of service (DoS) condition in the HTTP media server component of DJI drone firmware caused by insufficient connection and request rate limits. An attacker with network access to the drone can exhaust the server's connection pool by repeatedly requesting stored media files, causing the server to drop legitimate requests from the DJI Fly application. The attack requires local network access (adjacent network vector) and impacts the QuickTransfer media retrieval mode. Patches are available via firmware updates for all affected models.
Affected products
- DJI Neo before 01.00.0400
- DJI Neo 2 before 01.00.0500
- DJI Flip before 01.00.1200
- DJI Air 3 before 01.00.1600
- DJI Air 3S before 01.00.1400
- DJI Avata 2 before 01.00.0400
- DJI Avata 360 before 01.00.0300
- DJI Mavic 3 before 01.00.1400
- DJI Mavic 3 Classic before 01.00.0800
- DJI Mavic 3 Pro before 01.01.0700
- DJI Mavic 4 Pro before 01.00.0500
- DJI Mini 2 before 01.07.0200
- DJI Mini 3 before 01.00.0500
- DJI Mini 3 Pro before 01.00.0900
- DJI Mini 4 Pro before 01.00.1100
- DJI Mini 5 Pro before 01.00.0600
Timeline
- 2026-08-24: disclosed