
Proof-of-concept that passively sniffs cleartext BLE DUML traffic from DJI drones to recover Wi-Fi PSK and trusted session UUIDs, demonstrating CVE-2026-77812.
CVE record: https://www.cve.org/CVERecord?id=CVE-2026-77812
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-77812
DJI Drone expose a DUML control channel over Bluetooth. Every message on that channel — in both directions, between the DJI Fly app and the drone — is sent in the clear. No BLE link-layer encryption and no application-layer encryption are applied.
A passive attacker within radio range can read the full contents of every command and response, including:
No pairing, no interaction with the drone, and no prior trust relationship are required. Recovering the PSK lets the attacker join the drone's Wi-Fi network; recovering the UUID lets them present themselves as an already-trusted client.

| Product | Affected Version |
|---|---|
| DJI Neo | 0 – 01.00.0400 |
| DJI Neo 2 | 0 – 01.00.0500 |
| DJI Flip | 0 – 01.00.1200 |
| DJI Air 3 | 0 – 01.00.1600 |
| DJI Air 3S | 0 – 01.00.1400 |
| DJI Avata 2 | 0 – 01.00.0400 |
| DJI Avata 360 | 0 – 01.00.0300 |
| DJI Mavic 3 | 0 – 01.00.1400 |
| DJI Mavic 3 Classic | 0 – 01.00.0800 |
| DJI Mavic 3 Pro | 0 – 01.01.0700 |
| DJI Mavic 4 Pro | 0 – 01.00.0500 |
| DJI Mini 2 | 0 – 01.07.0200 |
| DJI Mini 3 | 0 – 01.00.0500 |
| DJI Mini 3 Pro | 0 – 01.00.0900 |
| DJI Mini 4 Pro | 0 – 01.00.1100 |
| DJI Mini 5 Pro | 0 – 01.00.0600 |
Capture is done with a Nordic nRF52840 Dongle running the nRF Sniffer for Bluetooth LE firmware. Programmed with that firmware, the dongle acts as a passive sniffer: it follows the advertising and data channels and forwards every received packet to the host over USB serial, where Wireshark decodes it.
poc.py.⚠️ WARNING: This proof of concept is intended strictly for educational, security-research, and authorized penetration-testing purposes.
⚠️ Do NOT use this POC against any aircraft, device, network, or system that you do not own or do not have explicit authorization to test.