CVE-2026-77812Patch

LOWCVSS 9.4 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to QuickTransfer mode, the DJI Fly application exchanges DUML messages with the drone over BLE, including the Wi-Fi credentials. An attacker within BLE range can passively sniff this traffic and recover the credentials in cleartext, including the drone's Wi-Fi PSK, SSID, and trusted identifier UUID. Obtaining these credentials allows the attacker to join the drone's internal Wi-Fi network, interact with network services exposed by the drone, and decrypt Wi-Fi traffic exchanged between the drone and the legitimate user. * An attacker within BLE range recovers the Wi-Fi SSID and PSK in cleartext, and can then join the drone's network * The same capture also exposes the session UUID identifier, which is the only thing the drone uses to tell a trusted client from an unknown one, so the attacker can replay it and skip the physical confirmation of new connected devices. * The credentials do not change between sessions unless the operator manually resets the Wi-Fi settings, so one capture stays valid indefinitely * The attack is fully passive, with nothing transmitted and no connection made, so neither the operator nor the drone has any indication the session was observed * A BLE sniffer and presence during one normal DJI Fly connection are needed Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor. There is no user-side mitigation that fully addresses the vulnerability without upgrading.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-311

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-23); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-23: 1Mentions · 2026-08-25: 1Mentions · 2026-09-20: 1PoC Mentioned / Linked · 2026-09-20: 1Patch / Workaround · 2026-08-23: 1Technical Details · 2026-08-23: 1Technical Details · 2026-08-25: 1Technical Details · 2026-09-20: 108-2308-2509-20
Signal classification3 categories
Patch
133.3%
Disclosure
133.3%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-231
Patch1
2026-08-251
Disclosure1
2026-09-201
PoC1
Full discourse3 posts
  • Abdelrahman Yousef@0xWh0_4m_1_
    Disclosure

    I found almost 8 zero day vulnerabilities affecting 15+ DJI drone models so far. CVE-2026-78306 — High (8.5) CVE-2026-78255 — High (8.7) CVE-2026-78251 — Critical (9.3) CVE-2026-78321 — Medium (6.0) CVE-2026-77812 — Critical (9.4) More CVEs on the way!! #DJI #CVE #BugBounty

    Post summary

    The notice announces the discovery of multiple zero-day vulnerabilities in DJI drone models, providing CVE identifiers and severity scores, but does not include proof-of-concept code, exploit details, patches, or evidence of active exploitation.

    00050405
    178 followersView on X
  • Abdelrahman Yousef@0xWh0_4m_1_
    PoC

    DJI drones leak their Wi-Fi credentials over Bluetooth. A passive attacker within BLE range can sniff the traffic, recover the SSID and PSK in plaintext, and join the drone’s internal network. PoC: https://github.com/Wh02m1/CVE-2026-77812 #DJI #BugBounty #ReverseEngineering #Firmware #CVE https://t.co/uieDh0sotk

    Post summary

    The tweet announces a DJI drone BLE vulnerability that exposes Wi-Fi credentials and links to a public GitHub PoC; no patch, named exploit tool, or active exploitation is reported.

    00031244
    178 followersView on X
  • lee1981@lee1981b
    Patch

    🔥 CyberForge CVE of the Day #031 🚨 CVE-2026-77812 — DJI has patched a Critical wireless flaw that can silently expose persistent drone Wi-Fi credentials and bypass trusted-client confirmation. During a normal DJI Fly Wi-Fi connection or QuickTransfer session, affected firmware sends sensitive DUML messages over Bluetooth Low Energy without encryption. A nearby listener can passively capture: 🔑 Wi-Fi SSID 🔑 Wi-Fi PSK 🔑 Trusted-client UUID ⚔️ The juicy chain: The PSK lets an attacker join the drone’s internal Wi-Fi. Replaying the UUID can make the device appear trusted, skipping the physical confirmation normally required for a new client. The advisory says this enables access to exposed aircraft services and decryption of drone/user Wi-Fi traffic. Those secrets persist across sessions until the owner resets the drone’s Wi-Fi settings—meaning one silent capture could remain useful later. 📷 Key details: ⭐ Severity: Critical — CVSS 9.4 ⭐ CWE-311: Missing Encryption ⭐ Vector: Adjacent/BLE range ⭐ Auth required: None ⭐ User interaction: None ⭐ Scope: 16 DJI Neo, Flip, Air, Avata, Mavic and Mini families ⭐ Public PoC: None identified ⭐ Active exploitation: None confirmed ⭐ CISA KEV: Not listed ⭐ EPSS: 0.062% initial estimate 🛡️ Defenders: Update every affected aircraft beyond its model-specific vulnerable firmware ceiling, verify the installed build, then reset its Wi-Fi settings and reconnect only trusted devices. Until patched, avoid unnecessary QuickTransfer/Wi-Fi sessions in crowded or untrusted locations. ⚠️ This is not internet-wide: The attacker must be nearby during a legitimate connection event. Evidence confirms credential exposure, Wi-Fi access and UUID replay—not proven flight hijacking, RCE or an aircraft-safety exploit. 🔗 Full visual advisory: https://github.com/advisories/GHSA-gh7r-589j-33x7 🔗 Full vulnerability details: https://nvd.nist.gov/vuln/detail/CVE-2026-77812 #CyberForge #CVEOfTheDay #CVE202677812 #DJI #DroneSecurity #BLE #WiFiSecurity #CyberSecurity

    Post summary

    The advisory confirms a critical DJI drone vulnerability, highlights the patch released by DJI, and provides detailed technical information, but reports no active exploitation or proof‑of‑concept.

    10010161
    562 followersView on X

Explore more