Skip to finding
important · Bluetooth — DJI

Public code lets a nearby attacker send unauthenticated management commands to DJI consumer drones over Bluetooth.

Affects

DJI Neo, Flip, Air, Avata, Mavic and Mini consumer aircraft using DJI Fly and QuickTransfer.

The demonstrated command set reaches Wi-Fi and radio configuration, storage operations, resets, wipes, reboot and power-off without pairing or a trusted UUID.

Detail and 4 sources

It does not establish that replacing the Wi-Fi credential grants flight-control authority.

Chain to watch
Use the public BLE console to replace the aircraft Wi-Fi credential.→↓Join the aircraft network and test each management and flight-control service for another authorization secret.→↓Whether the changed Wi-Fi credential alone reaches flight-control authority.
Unverified chainTest service authorization while the aircraft is safely restrained.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 26, 2026