PT-2026-79388 · Dji · Mavic 3+16
CVSS v4.0
9.4
Critical
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
DJI Neo versions prior to 01.00.0400
DJI Neo 2 versions prior to 01.00.0500
DJI Flip versions prior to 01.00.1200
DJI Air 3 versions prior to 01.00.1600
DJI Air 3S versions prior to 01.00.1400
DJI Avata 2 versions prior to 01.00.0400
DJI Avata 360 versions prior to 01.00.0300
DJI Mavic 3 versions prior to 01.00.1400
DJI Mavic 3 Classic versions prior to 01.00.0800
DJI Mavic 3 Pro versions prior to 01.01.0700
DJI Mavic 4 Pro versions prior to 01.00.0500
DJI Mini 2 versions prior to 01.07.0200
DJI Mini 3 versions prior to 01.00.0500
DJI Mini 3 Pro versions prior to 01.00.0900
DJI Mini 4 Pro versions prior to 01.00.1100
DJI Mini 5 Pro versions prior to 01.00.0600
Description
DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. During Wi-Fi connection attempts or when in QuickTransfer mode, the DJI Fly application exchanges DUML messages with the drone over BLE. An attacker within BLE range can passively sniff this traffic to recover cleartext credentials, including the Wi-Fi PSK, SSID, and the trusted identifier
UUID. This allows an attacker to join the drone's internal Wi-Fi network, interact with exposed network services, and decrypt Wi-Fi traffic between the drone and the user. Additionally, the captured UUID can be replayed to bypass physical confirmation for new connected devices. These credentials remain valid indefinitely unless the operator manually resets the Wi-Fi settings. The attack is entirely passive, leaving no indication to the operator or the drone that the session was observed.Recommendations
Update the firmware for DJI Neo to version 01.00.0400 or later.
Update the firmware for DJI Neo 2 to version 01.00.0500 or later.
Update the firmware for DJI Flip to version 01.00.1200 or later.
Update the firmware for DJI Air 3 to version 01.00.1600 or later.
Update the firmware for DJI Air 3S to version 01.00.1400 or later.
Update the firmware for DJI Avata 2 to version 01.00.0400 or later.
Update the firmware for DJI Avata 360 to version 01.00.0300 or later.
Update the firmware for DJI Mavic 3 to version 01.00.1400 or later.
Update the firmware for DJI Mavic 3 Classic to version 01.00.0800 or later.
Update the firmware for DJI Mavic 3 Pro to version 01.01.0700 or later.
Update the firmware for DJI Mavic 4 Pro to version 01.00.0500 or later.
Update the firmware for DJI Mini 2 to version 01.07.0200 or later.
Update the firmware for DJI Mini 3 to version 01.00.0500 or later.
Update the firmware for DJI Mini 3 Pro to version 01.00.0900 or later.
Update the firmware for DJI Mini 4 Pro to version 01.00.1100 or later.
Update the firmware for DJI Mini 5 Pro to version 01.00.0600 or later.
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Air 3
Air 3S
Avata 2
Avata 360
Dji Fly
Flip
Mavic 3
Mavic 3 Classic
Mavic 3 Pro
Mavic 4 Pro
Mini 2
Mini 3
Mini 3 Pro
Mini 4 Pro
Mini 5 Pro
Neo
Neo 2