CVE-CVE-2026-78306
Severity
UNKNOWN
CVSS Score
0.0
Description
DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect to the drone's internal Wi-Fi network, potentially gaining access to the flight control interface and issuing flight commands. Crafted DUML commands can also disable or restart the...
PoCs for CVE-CVE-2026-78306
CVE-2026-78306
SQL Injection
Python
7
Wh02m1
2026-09-20