Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2026-77812 — Proof-of-concept that passively sniffs cleartext BLE DUML traffic from DJI drones to recover Wi-Fi PSK and trusted session UUIDs, demonstrating CVE-2026-77812. | Kitploit
Herramientas/GitHubGitHub/wh02m1/cve-2026-77812
Packet Sniffing & AnalysisBluetooth SecurityVulnerability AnalysisExploitationInformation GatheringWireless SecurityHardware & IoT Security
GitHubwh02m1/cve-2026-77812

CVE-2026-77812

Proof-of-concept that passively sniffs cleartext BLE DUML traffic from DJI drones to recover Wi-Fi PSK and trusted session UUIDs, demonstrating CVE-2026-77812.

Ver Repositorio
1hace 8 díasAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

CVE-2026-77812 — DJI Drone Cleartext BLE Transmission of Wi-Fi PSK and Session UUID POC

CVE-2026-77812

CVE record: https://www.cve.org/CVERecord?id=CVE-2026-77812

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-77812

image

Description

DJI Drone expose a DUML control channel over Bluetooth. Every message on that channel — in both directions, between the DJI Fly app and the drone — is sent in the clear. No BLE link-layer encryption and no application-layer encryption are applied.

A passive attacker within radio range can read the full contents of every command and response, including:

  • the Wi-Fi SSID of the drone's access point,
  • the Wi-Fi PSK, returned by the drone in response to the GET Password command,
  • the trusted session UUID the app registers with the drone.

No pairing, no interaction with the drone, and no prior trust relationship are required. Recovering the PSK lets the attacker join the drone's Wi-Fi network; recovering the UUID lets them present themselves as an already-trusted client.

PSK recovered in plaintext Trusted session UUID recovered in plaintext

Affected Products

ProductAffected Version
DJI Neo0 – 01.00.0400
DJI Neo 20 – 01.00.0500
DJI Flip0 – 01.00.1200
DJI Air 30 – 01.00.1600
DJI Air 3S0 – 01.00.1400
DJI Avata 20 – 01.00.0400
DJI Avata 3600 – 01.00.0300
DJI Mavic 30 – 01.00.1400
DJI Mavic 3 Classic0 – 01.00.0800
DJI Mavic 3 Pro0 – 01.01.0700
DJI Mavic 4 Pro0 – 01.00.0500
DJI Mini 20 – 01.07.0200
DJI Mini 30 – 01.00.0500
DJI Mini 3 Pro0 – 01.00.0900
DJI Mini 4 Pro0 – 01.00.1100
DJI Mini 5 Pro0 – 01.00.0600

Reproduction

Setup

Capture is done with a Nordic nRF52840 Dongle running the nRF Sniffer for Bluetooth LE firmware. Programmed with that firmware, the dongle acts as a passive sniffer: it follows the advertising and data channels and forwards every received packet to the host over USB serial, where Wireshark decodes it.

  1. Flash the nRF52840 dongle with nRF Sniffer for BLE.
  2. Install the nRF Sniffer Wireshark extcap plugin.
  3. Start Wireshark, select the sniffer interface, and lock onto the drone's BLE address.
  4. Power on the drone and run a normal DJI Fly session (connect, then let the app fetch the Wi-Fi credentials).
  5. Save the captured pcap file in Wireshark after and give it to poc.py.

⚠️ Disclaimer

⚠️ WARNING: This proof of concept is intended strictly for educational, security-research, and authorized penetration-testing purposes.

⚠️ Do NOT use this POC against any aircraft, device, network, or system that you do not own or do not have explicit authorization to test.

Descargar herramienta