Abdelrahman Yousef

#6946of 56,335
41.9Total CVSS
Vulnerabilities · 5
Medium
1
High
2
Critical
2
PT-2026-79833
9.3
2026-08-24
Dji · Mavic 3 · CVE-2026-78251
**Name of the Vulnerable Software and Affected Versions** DJI Neo versions prior to 01.00.0400 DJI Neo 2 versions prior to 01.00.0500 DJI Flip versions prior to 01.00.1200 DJI Air 3 versions prior to 01.00.1600 DJI Air 3S versions prior to 01.00.1400 DJI Avata 2 versions prior to 01.00.0400 DJI Avata 360 versions prior to 01.00.0300 DJI Mavic 3 versions prior to 01.00.1400 DJI Mavic 3 Classic versions prior to 01.00.0800 DJI Mavic 3 Pro versions prior to 01.01.0700 DJI Mavic 4 Pro versions prior to 01.00.0500 DJI Mini 2 versions prior to 01.07.0200 DJI Mini 3 versions prior to 01.00.0500 DJI Mini 3 Pro versions prior to 01.00.0900 DJI Mini 4 Pro versions prior to 01.00.1100 DJI Mini 5 Pro versions prior to 01.00.0600 **Description** An FTP service uses hardcoded credentials shared across multiple models, allowing authenticated users to overwrite existing files or upload files without restrictions on size, count, or total storage in the `/blackbox/upgrade/` endpoint. An attacker with access to the internal network or USB RNDIS interface can exhaust available storage, which may prevent the aircraft from recording flight records, logs, and telemetry, and could block future firmware updates. Uploaded files remain on the device after a reboot or factory reset. **Recommendations** Update firmware for DJI Neo to version 01.00.0400 or later. Update firmware for DJI Neo 2 to version 01.00.0500 or later. Update firmware for DJI Flip to version 01.00.1200 or later. Update firmware for DJI Air 3 to version 01.00.1600 or later. Update firmware for DJI Air 3S to version 01.00.1400 or later. Update firmware for DJI Avata 2 to version 01.00.0400 or later. Update firmware for DJI Avata 360 to version 01.00.0300 or later. Update firmware for DJI Mavic 3 to version 01.00.1400 or later. Update firmware for DJI Mavic 3 Classic to version 01.00.0800 or later. Update firmware for DJI Mavic 3 Pro to version 01.01.0700 or later. Update firmware for DJI Mavic 4 Pro to version 01.00.0500 or later. Update firmware for DJI Mini 2 to version 01.07.0200 or later. Update firmware for DJI Mini 3 to version 01.00.0500 or later. Update firmware for DJI Mini 3 Pro to version 01.00.0900 or later. Update firmware for DJI Mini 4 Pro to version 01.00.1100 or later. Update firmware for DJI Mini 5 Pro to version 01.00.0600 or later.
PT-2026-79837
8.7
2026-08-24
Dji · Mavic 3 · CVE-2026-78255
**Name of the Vulnerable Software and Affected Versions** DJI Neo versions prior to 01.00.0400 DJI Neo 2 versions prior to 01.00.0500 DJI Flip versions prior to 01.00.1200 DJI Air 3 versions prior to 01.00.1600 DJI Air 3S versions prior to 01.00.1400 DJI Avata 2 versions prior to 01.00.0400 DJI Avata 360 versions prior to 01.00.0300 DJI Mavic 3 versions prior to 01.00.1400 DJI Mavic 3 Classic versions prior to 01.00.0800 DJI Mavic 3 Pro versions prior to 01.01.0700 DJI Mavic 4 Pro versions prior to 01.00.0500 DJI Mini 2 versions prior to 01.07.0200 DJI Mini 3 versions prior to 01.00.0500 DJI Mini 3 Pro versions prior to 01.00.0900 DJI Mini 4 Pro versions prior to 01.00.1100 DJI Mini 5 Pro versions prior to 01.00.0600 **Description** The HTTP media server on certain drones serves stored photos and videos through the `/v2` endpoint without requiring client authentication. Because filenames follow a predictable pattern, an attacker on the drone's internal network can enumerate filenames to exfiltrate media. This exposure may reveal sensitive data such as private locations, travel history, and identifiable individuals. **Recommendations** Update DJI Neo to version 01.00.0400 or later. Update DJI Neo 2 to version 01.00.0500 or later. Update DJI Flip to version 01.00.1200 or later. Update DJI Air 3 to version 01.00.1600 or later. Update DJI Air 3S to version 01.00.1400 or later. Update DJI Avata 2 to version 01.00.0400 or later. Update DJI Avata 360 to version 01.00.0300 or later. Update DJI Mavic 3 to version 01.00.1400 or later. Update DJI Mavic 3 Classic to version 01.00.0800 or later. Update DJI Mavic 3 Pro to version 01.01.0700 or later. Update DJI Mavic 4 Pro to version 01.00.0500 or later. Update DJI Mini 2 to version 01.07.0200 or later. Update DJI Mini 3 to version 01.00.0500 or later. Update DJI Mini 3 Pro to version 01.00.0900 or later. Update DJI Mini 4 Pro to version 01.00.1100 or later. Update DJI Mini 5 Pro to version 01.00.0600 or later.
PT-2026-79838
8.5
2026-08-24
Dji · Mavic 3 · CVE-2026-78306
**Name of the Vulnerable Software and Affected Versions** DJI Neo versions prior to 01.00.0400 DJI Neo 2 versions prior to 01.00.0500 DJI Flip versions prior to 01.00.1200 DJI Air 3 versions prior to 01.00.1600 DJI Air 3S versions prior to 01.00.1400 DJI Avata 2 versions prior to 01.00.0400 DJI Avata 360 versions prior to 01.00.0300 DJI Mavic 3 versions prior to 01.00.1400 DJI Mavic 3 Classic versions prior to 01.00.0800 DJI Mavic 3 Pro versions prior to 01.01.0700 DJI Mavic 4 Pro versions prior to 01.00.0500 DJI Mini 2 versions prior to 01.07.0200 DJI Mini 3 versions prior to 01.00.0500 DJI Mini 3 Pro versions prior to 01.00.0900 DJI Mini 4 Pro versions prior to 01.00.1100 DJI Mini 5 Pro versions prior to 01.00.0600 **Description** An unauthenticated DUML command interface is exposed over Bluetooth, allowing an attacker within range to modify Wi-Fi configuration parameters such as the SSID, PSK, MAC address, regulatory country code, and wireless channel. By overwriting the Wi-Fi PSK with a known value, an attacker can connect to the internal Wi-Fi network to potentially access the flight control interface and issue flight commands. Additionally, crafted DUML commands can disable or restart Wi-Fi and Bluetooth interfaces, disconnect clients, or reset wireless configurations, leading to a denial-of-service condition that disrupts wireless control, video, and telemetry connections during flight. **Recommendations** Update firmware for DJI Neo to version 01.00.0400 or later. Update firmware for DJI Neo 2 to version 01.00.0500 or later. Update firmware for DJI Flip to version 01.00.1200 or later. Update firmware for DJI Air 3 to version 01.00.1600 or later. Update firmware for DJI Air 3S to version 01.00.1400 or later. Update firmware for DJI Avata 2 to version 01.00.0400 or later. Update firmware for DJI Avata 360 to version 01.00.0300 or later. Update firmware for DJI Mavic 3 to version 01.00.1400 or later. Update firmware for DJI Mavic 3 Classic to version 01.00.0800 or later. Update firmware for DJI Mavic 3 Pro to version 01.01.0700 or later. Update firmware for DJI Mavic 4 Pro to version 01.00.0500 or later. Update firmware for DJI Mini 2 to version 01.07.0200 or later. Update firmware for DJI Mini 3 to version 01.00.0500 or later. Update firmware for DJI Mini 3 Pro to version 01.00.0900 or later. Update firmware for DJI Mini 4 Pro to version 01.00.1100 or later. Update firmware for DJI Mini 5 Pro to version 01.00.0600 or later.
PT-2026-79839
6.0
2026-08-24
Dji · Mavic 3 · CVE-2026-78321
**Name of the Vulnerable Software and Affected Versions** DJI Neo versions prior to 01.00.0400 DJI Neo 2 versions prior to 01.00.0500 DJI Flip versions prior to 01.00.1200 DJI Air 3 versions prior to 01.00.1600 DJI Air 3S versions prior to 01.00.1400 DJI Avata 2 versions prior to 01.00.0400 DJI Avata 360 versions prior to 01.00.0300 DJI Mavic 3 versions prior to 01.00.1400 DJI Mavic 3 Classic versions prior to 01.00.0800 DJI Mavic 3 Pro versions prior to 01.01.0700 DJI Mavic 4 Pro versions prior to 01.00.0500 DJI Mini 2 versions prior to 01.07.0200 DJI Mini 3 versions prior to 01.00.0500 DJI Mini 3 Pro versions prior to 01.00.0900 DJI Mini 4 Pro versions prior to 01.00.1100 DJI Mini 5 Pro versions prior to 01.00.0600 **Description** The HTTP media server fails to enforce sufficient limits on request rates or incoming connections. An attacker with access to the internal network can exhaust the server connection pool by repeatedly requesting stored media files. This results in a denial of service, preventing the DJI Fly application from retrieving photos and videos from the aircraft while in QuickTransfer mode. **Recommendations** Update firmware for DJI Neo to version 01.00.0400 or later. Update firmware for DJI Neo 2 to version 01.00.0500 or later. Update firmware for DJI Flip to version 01.00.1200 or later. Update firmware for DJI Air 3 to version 01.00.1600 or later. Update firmware for DJI Air 3S to version 01.00.1400 or later. Update firmware for DJI Avata 2 to version 01.00.0400 or later. Update firmware for DJI Avata 360 to version 01.00.0300 or later. Update firmware for DJI Mavic 3 to version 01.00.1400 or later. Update firmware for DJI Mavic 3 Classic to version 01.00.0800 or later. Update firmware for DJI Mavic 3 Pro to version 01.01.0700 or later. Update firmware for DJI Mavic 4 Pro to version 01.00.0500 or later. Update firmware for DJI Mini 2 to version 01.07.0200 or later. Update firmware for DJI Mini 3 to version 01.00.0500 or later. Update firmware for DJI Mini 3 Pro to version 01.00.0900 or later. Update firmware for DJI Mini 4 Pro to version 01.00.1100 or later. Update firmware for DJI Mini 5 Pro to version 01.00.0600 or later.
PT-2026-79388
9.4
2026-08-21
Dji · Mavic 3 · CVE-2026-77812
**Name of the Vulnerable Software and Affected Versions** DJI Neo versions prior to 01.00.0400 DJI Neo 2 versions prior to 01.00.0500 DJI Flip versions prior to 01.00.1200 DJI Air 3 versions prior to 01.00.1600 DJI Air 3S versions prior to 01.00.1400 DJI Avata 2 versions prior to 01.00.0400 DJI Avata 360 versions prior to 01.00.0300 DJI Mavic 3 versions prior to 01.00.1400 DJI Mavic 3 Classic versions prior to 01.00.0800 DJI Mavic 3 Pro versions prior to 01.01.0700 DJI Mavic 4 Pro versions prior to 01.00.0500 DJI Mini 2 versions prior to 01.07.0200 DJI Mini 3 versions prior to 01.00.0500 DJI Mini 3 Pro versions prior to 01.00.0900 DJI Mini 4 Pro versions prior to 01.00.1100 DJI Mini 5 Pro versions prior to 01.00.0600 **Description** DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. During Wi-Fi connection attempts or when in QuickTransfer mode, the DJI Fly application exchanges DUML messages with the drone over BLE. An attacker within BLE range can passively sniff this traffic to recover cleartext credentials, including the Wi-Fi PSK, SSID, and the trusted identifier `UUID`. This allows an attacker to join the drone's internal Wi-Fi network, interact with exposed network services, and decrypt Wi-Fi traffic between the drone and the user. Additionally, the captured `UUID` can be replayed to bypass physical confirmation for new connected devices. These credentials remain valid indefinitely unless the operator manually resets the Wi-Fi settings. The attack is entirely passive, leaving no indication to the operator or the drone that the session was observed. **Recommendations** Update the firmware for DJI Neo to version 01.00.0400 or later. Update the firmware for DJI Neo 2 to version 01.00.0500 or later. Update the firmware for DJI Flip to version 01.00.1200 or later. Update the firmware for DJI Air 3 to version 01.00.1600 or later. Update the firmware for DJI Air 3S to version 01.00.1400 or later. Update the firmware for DJI Avata 2 to version 01.00.0400 or later. Update the firmware for DJI Avata 360 to version 01.00.0300 or later. Update the firmware for DJI Mavic 3 to version 01.00.1400 or later. Update the firmware for DJI Mavic 3 Classic to version 01.00.0800 or later. Update the firmware for DJI Mavic 3 Pro to version 01.01.0700 or later. Update the firmware for DJI Mavic 4 Pro to version 01.00.0500 or later. Update the firmware for DJI Mini 2 to version 01.07.0200 or later. Update the firmware for DJI Mini 3 to version 01.00.0500 or later. Update the firmware for DJI Mini 3 Pro to version 01.00.0900 or later. Update the firmware for DJI Mini 4 Pro to version 01.00.1100 or later. Update the firmware for DJI Mini 5 Pro to version 01.00.0600 or later.