CVE-2026-77812: DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encry
Summary
DJI drones send unencrypted DUML (DJI Universal Markup Language, a protocol for communicating with the drone) messages over BLE (Bluetooth Low Energy, a wireless communication method), exposing Wi-Fi passwords and network identifiers to attackers within Bluetooth range. An attacker can passively intercept these credentials without the drone or user knowing, then join the drone's network and access its services. Since credentials don't change unless manually reset, a single interception gives an attacker permanent access.
Solution / Mitigation
Remediation requires a firmware update from the vendor. There is no user-side mitigation that fully addresses the vulnerability without upgrading. Specific patched firmware versions are: DJI Neo 01.00.0400+, DJI Neo 2 01.00.0500+, DJI Flip 01.00.1200+, DJI Air 3 01.00.1600+, DJI Air 3S 01.00.1400+, DJI Avata 2 01.00.0400+, DJI Avata 360 01.00.0300+, DJI Mavic 3 01.00.1400+, DJI Mavic 3 Classic 01.00.0800+, DJI Mavic 3 Pro 01.01.0700+, DJI Mavic 4 Pro 01.00.0500+, DJI Mini 2 01.07.0200+, DJI Mini 3 01.00.0500+, DJI Mini 3 Pro 01.00.0900+, DJI Mini 4 Pro 01.00.1100+, and DJI Mini 5 Pro 01.00.0600+.
Vulnerability Details
EPSS: 0.0%
August 21, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-77812
First tracked: August 21, 2026 at 02:07 PM
Classified by LLM (prompt v3) · confidence: 95%