ZeroHour

CVE-2026-78251

mass

Hardcoded FTP credentials in DJI drones enable storage-exhaustion attacks

CVSS 4.0
9.3 critical
EPSS
<1%p32
Published
()
Modified
AI analysis

The FTP service embedded in the firmware of numerous DJI consumer drones uses hardcoded credentials shared across affected models (CWE-798) and permits authenticated users to upload files of unlimited size, count, and total storage to the /blackbox/upgrade/ directory, where existing files can also be overwritten. An attacker who can reach the drone's internal network or its USB RNDIS interface can authenticate with the shared credentials and deliberately fill the onboard storage. Successful abuse prevents the aircraft from writing flight records, logs, and telemetry, may block subsequent firmware updates, and the uploaded files persist across reboot and factory reset, complicating recovery. Sixteen DJI models are affected — the Neo, Neo 2, Flip, Air 3, Air 3S, Avata 2, Avata 360, Mavic 3, Mavic 3 Classic, Mavic 3 Pro, Mavic 4 Pro, Mini 2, Mini 3, Mini 3 Pro, Mini 4 Pro, and Mini 5 Pro — each at firmware versions below the listed fixed builds, with remediation requiring a vendor firmware update. No public proof-of-concept is known, the issue is not in CISA's KEV, and EPSS assigns only a 0.4% probability of exploitation within 30 days, so no in-the-wild exploitation is currently known.

What to do: Update each affected aircraft to at least the listed fixed firmware for its model (e.g., Neo 01.00.0400, Mavic 3 Pro 01.01.0700, Mini 2 01.07.0200) via DJI's official update tooling, and verify the current firmware version in the DJI mobile app. Until updated, avoid connecting affected drones to untrusted Wi-Fi networks and disconnect USB RNDIS links when not in use, since exploitation requires access to the drone's internal network or USB interface. If storage was filled, note that uploaded files persist through reboot and factory reset, so manually clear /blackbox/upgrade/ where possible.

Affected
DJI NeoFirmware below 01.00.0400 (fixed in 01.00.0400)
DJI Neo 2Firmware below 01.00.0500 (fixed in 01.00.0500)
DJI FlipFirmware below 01.00.1200 (fixed in 01.00.1200)
DJI Air 3Firmware below 01.00.1600 (fixed in 01.00.1600)
DJI Air 3SFirmware below 01.00.1400 (fixed in 01.00.1400)
DJI Avata 2Firmware below 01.00.0400 (fixed in 01.00.0400)
DJI Avata 360Firmware below 01.00.0300 (fixed in 01.00.0300)
DJI Mavic 3Firmware below 01.00.1400 (fixed in 01.00.1400)
DJI Mavic 3 ClassicFirmware below 01.00.0800 (fixed in 01.00.0800)
DJI Mavic 3 ProFirmware below 01.01.0700 (fixed in 01.01.0700)
DJI Mavic 4 ProFirmware below 01.00.0500 (fixed in 01.00.0500)
DJI Mini 2Firmware below 01.07.0200 (fixed in 01.07.0200)
Estimated exposure
mass≈ millions of drones worldwide (16 mainstream consumer models from the dominant consumer drone vendor) — DJI holds an estimated ~70% share of the consumer drone market and the affected list spans its best-selling recent product lines (Mini, Mavic 3, Air 3, Avata, Neo, Flip), so the installed base of vulnerable aircraft is plausibly in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in that directory. An attacker with access to the drone's internal network or USB RNDIS interface can exhaust the available storage, preventing the aircraft from writing flight records, logs, and telemetry and potentially preventing subsequent firmware updates. Uploaded files persist across reboot and factory reset. Affected models are DJI Neo until 01.00.0400, DJI Neo 2 until 01.00.0500, DJI Flip until 01.00.1200, DJI Air 3 until 01.00.1600, DJI Air 3S until 01.00.1400, DJI Avata 2 until 01.00.0400, DJI Avata 360 until 01.00.0300, DJI Mavic 3 until 01.00.1400, DJI Mavic 3 Classic until 01.00.0800, DJI Mavic 3 Pro until 01.01.0700, DJI Mavic 4 Pro until 01.00.0500, DJI Mini 2 until 01.07.0200, DJI Mini 3 until 01.00.0500, DJI Mini 3 Pro until 01.00.0900, DJI Mini 4 Pro until 01.00.1100, and DJI Mini 5 Pro until 01.00.0600. Remediation requires a firmware update from the vendor.

Weakness
CWE-798
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.