CVE-2026-78306Disclosure

MEDIUMCVSS 8.5 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect to the drone's internal Wi-Fi network, potentially gaining access to the flight control interface and issuing flight commands. Crafted DUML commands can also disable or restart the Wi-Fi and Bluetooth interfaces, disconnect Wi-Fi clients, or reset wireless configuration, resulting in a denial-of-service condition that can disrupt the operator's wireless control, video, and telemetry connections during flight. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-09-20); latest day: 2
  • 10 total mentions across 6 days

Deep dive

Activity timeline10 mentions / 6d
01223Mentions · 2026-08-24: 2Mentions · 2026-08-25: 1Mentions · 2026-09-20: 3Mentions · 2026-09-21: 1Mentions · 2026-09-23: 1Mentions · 2026-09-28: 2PoC Mentioned / Linked · 2026-09-20: 2Exploit Tool / Code · 2026-09-20: 1Patch / Workaround · 2026-09-23: 1Technical Details · 2026-08-24: 1Technical Details · 2026-08-25: 1Technical Details · 2026-09-20: 2Technical Details · 2026-09-21: 1Technical Details · 2026-09-23: 108-2408-2509-2009-2109-2309-28
Signal classification3 categories
Disclosure
450.0%
General
225.0%
PoC
225.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-242
Disclosure1General1
2026-08-251
Disclosure1
2026-09-203
General1PoC2
2026-09-211
Disclosure1
2026-09-231
Disclosure1
Full discourse10 posts
  • Abdelrahman Yousef@0xWh0_4m_1_
    PoC

    Breaking a DJI drone starts with Bluetooth 📶 Published the PoC for CVE-2026-78306, an unauthenticated Bluetooth DUML vulnerability affecting DJI drones. 🔗 https://github.com/Wh02m1/CVE-2026-78306 More POCs on the way! #DJI #Bugbounty #ReverseEngineering #Firmware #CVE

    Post summary

    The post's main focus is announcing that a PoC for CVE-2026-78306, an unauthenticated Bluetooth DUML vulnerability in DJI drones, has been published with a GitHub link. It does not report active exploitation or provide patch guidance.

    14097747
    178 followersView on X
  • Abdelrahman Yousef@0xWh0_4m_1_
    PoC

    CVE-2026-78306 — DJI Drone Vulnerability DJI drones expose a Bluetooth channel that allows an attacker to send commands without authentication. POC👇 #DJI #bugbounty #CyberSecurity #CVE #DroneSecurity #ReverseEngineering https://t.co/itqbJLXjyr

    Post summary

    The tweet reports CVE‑2026‑78306 affecting DJI drones via an unauthenticated Bluetooth command channel and shares a PoC link.

    421912.0K
    178 followersView on X
  • Ryx@PadhiyarRushi

    Bluetooth-range DUML on DJI. Change the Wi-Fi PSK, join the aircraft, fly it! CVE-2026-78306: Trusted UUID is checked for Get SSID / Get Password / Get MAC only. Every other DUML command skips that gate. Overwrite PSK, hop onto the internal AP, hit flight control. Same path can kill Wi-Fi/BT mid-flight. PoC repo is public. Neo, Flip, Air 3/3S, Avata 2, Mavic 3/4, Mini 2–5 Pro on the listed firmware! https://github.com/Wh02m1/CVE-2026-78306 #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #IoT #Drone #Bluetooth

    010104622
    954 followersView on X
  • Abdelrahman Yousef@0xWh0_4m_1_
    Disclosure

    I found almost 8 zero day vulnerabilities affecting 15+ DJI drone models so far. CVE-2026-78306 — High (8.5) CVE-2026-78255 — High (8.7) CVE-2026-78251 — Critical (9.3) CVE-2026-78321 — Medium (6.0) CVE-2026-77812 — Critical (9.4) More CVEs on the way!! #DJI #CVE #BugBounty

    Post summary

    The author reports discovery of multiple zero‑day CVEs affecting DJI drones, listing their IDs and severity levels.

    00050405
    178 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    The DJI Bluetooth vulnerability CVE-2026-78306 lets a nearby attacker send unauthenticated DUML commands to 16 drone models. Update firmware now. #DJI #CVE202678306 #Bluetooth #DroneSecurity #DUML #CyberSecurity https://meterpreter.org/dji-bluetooth-vulnerability/

    Post summary

    The tweet discloses CVE-2026-78306, detailing a Bluetooth vulnerability enabling unauthenticated DUML commands on 16 DJI drone models, and urges firmware updates without naming a specific patch, advisory, or fixed version, resulting in a Disclosure classification.

    00030544
    13.0K followersView on X
  • Abdullah@vm_32
    Disclosure

    ثغرة في Bluetooth قد تكون كافية لمنح مهاجم قريب القدرة على تغيير إعدادات الاتصال في بعض طائرات DJI، وقطع الارتباط مع الطيار، والتأثير في عدد من مكونات النظام. في المقال أشرح تفاصيل CVE-2026-78306، وآلية عملها، وما الذي أثبته الباحثون فعليًا، وأين تبدأ سيناريوهات الاستيلاء المحتملة. رابط المقال: https://vm32.com/articles/8fcbb444-effc-48d1-bca1-fb744bb721d4

    Post summary

    The text discloses CVE-2026-78306, a Bluetooth vulnerability affecting DJI drones that could allow a nearby attacker to alter connection settings, disconnect the pilot, and impact system components, with technical details provided but no mention of patches, exploits, or active exploitation.

    10011295
    35 followersView on X
  • Abdelrahman Yousef@0xWh0_4m_1_
    General

    https://github.com/Wh02m1/CVE-2026-78306

    Post summary

    The text is a URL linking to a GitHub repository named after CVE-2026-78306, but it lacks any specific details about the vulnerability, exploitation, or remediation, making it a general reference.

    00002238
    175 followersView on X
  • SurNoticias@surnoticiasperu

    Grave vulnerabilidad Bluetooth en drones DJI podría permitir a hackers interferir con el vuelo y tomar el control https://somoslibres.org/103-ciberseguridad/14952-vulnerabilidad-bluetooth-drones-dji-hackers-control-vuelo-cve-2026-78306 https://t.co/OYYstptvAG

    0000037
    1.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-78306 DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, in… https://www.cve.org/CVERecord?id=CVE-2026-78306

    Post summary

    DJI drones expose a Bluetooth‑based command interface that lets attackers within range change Wi‑Fi settings. No PoC or active exploitation evidence is presented, but the vulnerability details are explicitly described.

    00000758
    58.0K followersView on X
  • VulDB 🛡@vuldb
    General

    We have just added an important vulnerability affecting DJI Air 3 and other products (CVE-2026-78306) https://vuldb.com/vuln/394605

    Post summary

    The tweet announces the existence of CVE-2026-78306 for DJI Air 3, linking to a Vuldb page, but offers no further technical, exploit, or patch details.

    00000151
    2.3K followersView on X

Explore more