DJI Bluetooth Flaw Lets Nearby Attackers Hijack Drones
A DJI drone may keep hovering in the air while a nearby attacker, without any password, alters its connectivity settings, reboots the aircraft, or attempts to sever the pilot from control.
The problem has received the identifier CVE-2026-78306, rated 8.5 out of 10 on CVSS 4.0, at the High severity level. The vulnerability affects 16 DJI models across the Neo, Flip, Air, Avata, Mavic, and Mini families. Exploitation requires no account, no system privileges, and no action from the owner, but the attacker must be within Bluetooth range. Such Bluetooth attacks are especially dangerous for devices where the wireless interface is tied to control functions.
Where the Weakness Lies
The weak point lies in the handling of commands from DJI’s proprietary DUML protocol, through which the drone’s components exchange service data. The Bluetooth interface checks a trusted UUID for only three operations, those tied to retrieving the Wi-Fi network name, password, and MAC address. No equivalent check exists for the remaining commands, so the drone can accept an instruction from an outside device.
Researcher Jordan Samhi discovered the flaw. The authors of the proof of concept confirmed the ability to change the Wi-Fi SSID and password, switch radio interfaces on and off, restart Bluetooth and Wi-Fi, reboot or power off the aircraft, reset the settings of various subsystems, and delete saved data. Some commands touch the flight controller, camera, stabilizer, and software-defined radio module.
The Most Serious Scenario
The most serious scenario begins with changing the Wi-Fi password to a value known to the attacker. After that, an outside device could potentially connect to the drone’s internal network and reach the flight-control interface. For unmanned aircraft, the stability of the radio link directly affects flight safety, since control, telemetry, and video all travel over that channel.
A full mid-air takeover of a DJI drone remains, for now, a possible continuation of the attack rather than a confirmed experimental result. The researchers did not demonstrate transmitting flight commands after penetrating the internal network. However, loss of connection with the operator, configuration changes, and equipment restarts are confirmed, so the consequences could prove serious even without a full takeover of control.
Affected Models and the Fix
The list of affected devices includes the DJI Neo and Neo 2, Flip, Air 3 and Air 3S, Avata 2 and Avata 360, Mavic 3, Mavic 3 Classic, Mavic 3 Pro, and Mavic 4 Pro, as well as the Mini 2, Mini 3, Mini 3 Pro, Mini 4 Pro, and Mini 5 Pro. The CVE record recommends installing the manufacturer’s current firmware. There are as yet no reports of the vulnerability being exploited in real attacks.
The researchers published a detailed technical description and proof-of-concept code, though they gated the dangerous commands behind an additional confirmation and a warning about the risk of losing connectivity, data, and configuration. The tool is intended for testing on one’s own equipment and in a controlled environment.
Not DJI’s First Bluetooth Stumble
DJI has faced weaknesses in its QuickTransfer mechanism before. During an analysis of the Mavic 3, specialists found problems in Wi-Fi password generation, network services, and the API for accessing media data. Some of these errors let an attacker who reached the drone’s wireless network substantially widen the scope of the attack.
Weak authentication in a control channel is dangerous well beyond DJI. The ExpressLRS protocol was earlier found to have pairing errors that let an attacker recover the link identifier and prepare their own transmitter to control a drone. In both cases, the chief security boundary becomes the verification of exactly who holds the right to send commands to an aircraft.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.