CVE-2020-29664: OS Command Injection
Published Feb 18, 2021
·Updated
A command injection issue in djisys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious firmware upgrade packet.
Affected Software
2 affected components
DJI Mavic 2 Firmware<01.00.0510
DJI Mavic 2
Event History
Feb 18, 2021
CVE Published
via MITRE·12:59 PM
Data Sourced
via MITRE·12:59 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-29664?
CVE-2020-29664 is classified as a critical severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2020-29664?
To mitigate CVE-2020-29664, users should upgrade their DJI Mavic 2 Remote Controller firmware to version 01.00.0510 or later.
3
What kind of attack does CVE-2020-29664 enable?
CVE-2020-29664 allows attackers to execute arbitrary code through a malicious firmware upgrade packet.
4
Which devices are affected by CVE-2020-29664?
CVE-2020-29664 affects the DJI Mavic 2 Remote Controller operating with firmware versions prior to 01.00.0510.
5
Is CVE-2020-29664 reversible after I update?
Once the firmware is updated to version 01.00.0510 or later, CVE-2020-29664 is no longer a threat.