CVE-2025-10250: DJI Mavic Spark/Mavic Air/Mavic Mini Telemetry Channel hard-coded key
A weakness has been identified in DJI Mavic Spark, Mavic Air and Mavic Mini 01.00.0500. Affected is an unknown function of the component Telemetry Channel. Executing manipulation can lead to use of hard-coded cryptographic key . The attacker needs to be present on the local network. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been made available to the public and could be exploited. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What are the main products affected by CVE-2025-10250?
The main products affected by CVE-2025-10250 are the DJI Mavic Spark, Mavic Air, and Mavic Mini.
What is the impact of CVE-2025-10250?
CVE-2025-10250 can allow an attacker on the local network to exploit a weakness in the Telemetry Channel to use a hard-coded cryptographic key.
How can I mitigate CVE-2025-10250?
To mitigate CVE-2025-10250, ensure that your devices are updated to the latest firmware version and configure network security measures to limit unauthorized access.
Is it necessary to be on the local network to exploit CVE-2025-10250?
Yes, an attacker needs to be present on the local network to exploit CVE-2025-10250.
What type of vulnerability is CVE-2025-10250 classified as?
CVE-2025-10250 is classified as a weakness within the Telemetry Channel component of the affected DJI products.