CVE-CVE-2026-77812
Severity
UNKNOWN
CVSS Score
0.0
Description
DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to QuickTransfer mode, the DJI Fly application exchanges DUML messages with the drone over BLE, including the Wi-Fi credentials. An attacker within BLE range can passively sniff this traffic and recover the credentials in cleartext, including the drone's Wi-Fi PSK, SSID, and trusted ...
PoCs for CVE-CVE-2026-77812
CVE-2026-77812
General
Python
0
Wh02m1
2026-09-20