Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2026-78306 — Proof-of-concept exploiting DJI drone Bluetooth DUML command injection, sending unauthenticated commands to read credentials, alter Wi-Fi config, and control aircraft systems. | Kitploit
Herramientas/GitHubGitHub/wh02m1/cve-2026-78306
Embedded Systems SecurityBluetooth SecurityIoT SecurityPayload GenerationVulnerability AnalysisExploitationWireless SecurityPenetration TestingHardware & IoT Security
GitHubwh02m1/cve-2026-78306

CVE-2026-78306

Proof-of-concept exploiting DJI drone Bluetooth DUML command injection, sending unauthenticated commands to read credentials, alter Wi-Fi config, and control aircraft systems.

18677hace 11 díasAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Ver Repositorio
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

CVE-2026-78306 — DJI Drone DUML Command Injection over Bluetooth POC

CVE-2026-78306

CVE record: https://www.cve.org/CVERecord?id=CVE-2026-78306

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-78306

image

Description

DJI drones expose a Bluetooth interface used to establish a connection to the drone's Wi-Fi interface and exchange Wi-Fi credentials

The Bluetooth interface checks the device's trusted UUID for three commands:

  • Get Wifi SSID
  • Get Wifi Password
  • Get Wifi MAC address

The remaining commands do not require the same authentication check. As a result, a remote attacker within Bluetooth range may be able to send unauthorized DUML commands to the drone.

Depending on the command, an attacker may be able to modify the drone's configuration, including changing the Wi-Fi password and potentially gaining access to the drone's internal network; enabling or disabling radio interfaces; restarting or powering off the aircraft; resetting the configuration, which wipes all videos and pictures captured by the drone; and performing other actions.

Note: The exploit currently works in-flight when controlling the drone over Wi-Fi, and on the ground/when drone land when controlling the drone over radio.

Affected Products

ProductAffected Version
DJI Neo0 – 01.00.0400
DJI Neo 20 – 01.00.0500
DJI Flip0 – 01.00.1200
DJI Air 30 – 01.00.1600
DJI Air 3S0 – 01.00.1400
DJI Avata 20 – 01.00.0400
DJI Avata 3600 – 01.00.0300
DJI Mavic 30 – 01.00.1400
DJI Mavic 3 Classic0 – 01.00.0800
DJI Mavic 3 Pro0 – 01.01.0700
DJI Mavic 4 Pro0 – 01.00.0500
DJI Mini 20 – 01.07.0200
DJI Mini 30 – 01.00.0500
DJI Mini 3 Pro0 – 01.00.0900
DJI Mini 4 Pro0 – 01.00.1100
DJI Mini 5 Pro0 – 01.00.0600

DEMO

https://github.com/user-attachments/assets/57f51df2-5160-404c-9fd3-2a3a8b700008

Installation

1. Install the POC

# Clone the repository
git clone https://github.com/Wh02m1/CVE-2026-78306.git
cd CVE-2026-78306-POC

# Create and activate a Python virtual environment
python3 -m venv venv
source venv/bin/activate

# Install dependencies
pip install -r requirements.txt

2. Power on the drone

3. Run the POC

python3 ble_console.py

4. After scan select the Drone SSID

Command Reference

The following commands are registered in commands.json and are generated directly from it. Commands marked danger require explicit confirmation before being sent.

Read Commands

CommandWhat it does
GET WiFi SSID [AUTH]Retrieves the configured Wi-Fi SSID. Requires a trusted UUID.
GET WiFi Password [AUTH]Retrieves the Wi-Fi WPA2 pre-shared key. Requires a trusted UUID.
GET WiFi MAC address [AUTH]Retrieves the Wi-Fi AP MAC address. Requires a trusted UUID.
GET Country CodeRetrieves the two-letter regulatory country code.
GET ChannelRetrieves the currently active Wi-Fi channel.
GET BandRetrieves the configured 2.4/5 GHz band selection.
GET RSSI [stub]Queries the RSSI handler; this build returns a stub value.
GET WiFi/BT statusRetrieves the Wi-Fi and Bluetooth radio state.
GET VersionRetrieves the firmware version string.

Write Configuration Commands

CommandWhat it does
SET NEW WiFi SSIDChanges the configured Wi-Fi SSID.
SET NEW WiFi PasswordChanges the configured Wi-Fi password.
SET NEW WiFi MAC AddressChanges the runtime Wi-Fi BSSID configuration.
SET NEW Country CodeChanges the configured regulatory country code.
SET NEW Country Code ExtHandles extended country-code configuration.
SET NEW ChannelChanges the Wi-Fi channel and causes the AP to restart.

These operations are classified as danger in the POC and therefore require explicit confirmation before being sent.

Radio Control Commands

CommandWhat it does
Start WiFiStarts the Wi-Fi interface.
Stop WiFiStops the Wi-Fi interface.
Restart WiFi + BluetoothRestarts the Wi-Fi and Bluetooth radios.
Start BluetoothStarts the Bluetooth radio.
Stop BluetoothStops the Bluetooth radio and terminates the current session.
Sysmode power controlControls the Wi-Fi/Bluetooth radio power state.

Reset Commands

CommandWhat it does
Factory Reset WIFIRestores the Wi-Fi configuration to its default state.
Factory Restore ParamsRestores the network configuration to factory defaults.

The POC marks both operations as dangerous because they modify persistent configuration.

System Commands

CommandWhat it does
Start The Drone FTP serverStarts the aircraft's FTP service.
Enable Storage ExportEnables storage export.
Disable Storage ExportDisables storage export.
reboot The DroneReboots the aircraft.
poweroff The DronePowers off the aircraft (physical access needed to power back on).
powersave mode The DronePlaces the aircraft into power-save mode.

Remote Controller DoS Commands

CommandWhat it does
Start Remote Controller DoSFirst step of the remote-controller denial-of-service sequence; puts the aircraft into the state the disconnect step requires.
Stop Remote Controller DoSCompletes the sequence: the aircraft stops servicing the controller link, so the remote controller loses the aircraft. Run the first step beforehand.
Remote Controller RecoverAttempts to return the aircraft to normal operation.

Parameter Commands

CommandWhat it does
Change a parameterChanges a drone configuration parameter using its 32-bit name hash.
Reset a parameterResets a configuration parameter to its firmware default.

The POC obtains parameter names from flyc_parameters.txt and provides interactive parameter selection. To add a known parameter that you want to modify or reset, add its name to flyc_parameters.txt. The parameter will then be available for selection when the POC is started.

Confirmation Screen

Commands classified as danger require explicit confirmation before transmission.

The confirmation screen displays information such as:

──────────────────────────────────────────────────────────────────────
  !!!  DANGEROUS COMMAND  !!!
──────────────────────────────────────────────────────────────────────
 COMMAND    Factory Reset WIFI
 ROUTE      07/0f → 0x07
 PAYLOAD    (none)
 DOES       resets the Wi-Fi config and regenerates the PSK
 WARNING    Disconnects every device currently on the drone's Wi-Fi.
──────────────────────────────────────────────────────────────────────
 Type YES to send:

Parameters

The Change a parameter function provides access to the known configuration parameters listed in flyc_parameters.txt.

Reset a parameter uses reset_cfg_item to restore the selected parameter to its firmware default.

For a complete list of the extracted parameters and more details, see the FLYC Parameters wiki page.


Macros

The POC also provides several predefined macros:

Descargar herramienta