CVE-2026-78306: DJI Drone Bluetooth Interface Unauthenticated DUML Command Execution
DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect to the drone's internal Wi-Fi network, potentially gaining access to the flight control interface and issuing flight commands. Crafted DUML commands can also disable or restart the Wi-Fi and Bluetooth interfaces, disconnect Wi-Fi clients, or reset wireless configuration, resulting in a denial-of-service condition that can disrupt the operator's wireless control, video, and telemetry connections during flight.
Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600.
Remediation requires a firmware update from the vendor.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DJI Neoto a version that resolves this vulnerability.Fixed in 01.00.0400 - Upgrade
Upgrade
DJI Neo 2to a version that resolves this vulnerability.Fixed in 01.00.0500 - Upgrade
Upgrade
DJI Flipto a version that resolves this vulnerability.Fixed in 01.00.1200 - Upgrade
Upgrade
DJI Air 3to a version that resolves this vulnerability.Fixed in 01.00.1600 - Upgrade
Upgrade
DJI Air 3Sto a version that resolves this vulnerability.Fixed in 01.00.1400 - Upgrade
Upgrade
DJI Avata 2to a version that resolves this vulnerability.Fixed in 01.00.0400 - Upgrade
Upgrade
DJI Avata 360to a version that resolves this vulnerability.Fixed in 01.00.0300 - Upgrade
Upgrade
DJI Mavic 3to a version that resolves this vulnerability.Fixed in 01.00.1400 - Upgrade
Upgrade
DJI Mavic 3 Classicto a version that resolves this vulnerability.Fixed in 01.00.0800 - Upgrade
Upgrade
DJI Mavic 3 Proto a version that resolves this vulnerability.Fixed in 01.01.0700 - Upgrade
Upgrade
DJI Mavic 4 Proto a version that resolves this vulnerability.Fixed in 01.00.0500 - Upgrade
Upgrade
DJI Mini 2to a version that resolves this vulnerability.Fixed in 01.07.0200 - Upgrade
Upgrade
DJI Mini 3to a version that resolves this vulnerability.Fixed in 01.00.0500 - Upgrade
Upgrade
DJI Mini 3 Proto a version that resolves this vulnerability.Fixed in 01.00.0900 - Upgrade
Upgrade
DJI Mini 4 Proto a version that resolves this vulnerability.Fixed in 01.00.1100 - Upgrade
Upgrade
DJI Mini 5 Proto a version that resolves this vulnerability.Fixed in 01.00.0600
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be within Bluetooth range of the drone. The DUML command interface does not require authentication.
How can I determine whether a drone is affected?
Affected devices include the listed models running firmware earlier than their specified fixed version, such as DJI Neo before 01.00.0400, DJI Neo 2 before 01.00.0500, DJI Flip before 01.00.1200, DJI Air 3 before 01.00.1600, and DJI Air 3S before 01.00.1400. Compare the drone model and installed firmware version with the affected-version information.
What could an attacker do after reaching the Bluetooth interface?
An attacker can change Wi-Fi parameters, including the PSK, then use a known PSK to join the drone's internal Wi-Fi network. They can also disable or restart Wi-Fi and Bluetooth, disconnect Wi-Fi clients, or reset wireless settings, disrupting control, video, and telemetry connections during flight.