important · Bluetooth — DJI
Public code lets a nearby attacker send unauthenticated management commands to DJI consumer drones over Bluetooth.
Affects
DJI Neo, Flip, Air, Avata, Mavic and Mini consumer aircraft using DJI Fly and QuickTransfer.
The demonstrated command set reaches Wi-Fi and radio configuration, storage operations, resets, wipes, reboot and power-off without pairing or a trusted UUID.
Detail and 4 sources
It does not establish that replacing the Wi-Fi credential grants flight-control authority.
Chain to watch
Use the public BLE console to replace the aircraft Wi-Fi credential.→↓Join the aircraft network and test each management and flight-control service for another authorization secret.→↓Whether the changed Wi-Fi credential alone reaches flight-control authority.
Unverified chainTest service authorization while the aircraft is safely restrained.
Sources
ResearchCVE-2026-78306: DJI Neo, Neo 2, Flip Vulnerability | CVETodoResearchGuidelines and FAQs for QuickTransferCode / PoCGitHub - Wh02m1/CVE-2026-78306: DJI Drone DUML Command Injection over Bluetooth — Proof of Concept for CVE-2026-78306 · GitHubCode / PoCCVE-2026-78306 - GitHub Advisory Database