Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

FeedContattoPrivacy© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
Strumenti/GitHubGitHub/wh02m1/cve-2026-77812
Packet Sniffing & AnalysisBluetooth SecurityVulnerability AnalysisExploitationInformation GatheringWireless SecurityHardware & IoT Security
GitHubwh02m1/cve-2026-77812

CVE-2026-77812

Proof-of-concept that passively sniffs cleartext BLE DUML traffic from DJI drones to recover Wi-Fi PSK and trusted session UUIDs, demonstrating CVE-2026-77812.

Vedi Repository
18 giorni faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
Contenuto non disponibile nella lingua richiesta. Visualizzazione della versione inglese.

CVE-2026-77812 — DJI Drone Cleartext BLE Transmission of Wi-Fi PSK and Session UUID POC

CVE-2026-77812

CVE record: https://www.cve.org/CVERecord?id=CVE-2026-77812

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-77812

image

Description

DJI Drone expose a DUML control channel over Bluetooth. Every message on that channel — in both directions, between the DJI Fly app and the drone — is sent in the clear. No BLE link-layer encryption and no application-layer encryption are applied.

A passive attacker within radio range can read the full contents of every command and response, including:

  • the Wi-Fi SSID of the drone's access point,
  • the Wi-Fi PSK, returned by the drone in response to the GET Password command,
  • the trusted session UUID the app registers with the drone.

No pairing, no interaction with the drone, and no prior trust relationship are required. Recovering the PSK lets the attacker join the drone's Wi-Fi network; recovering the UUID lets them present themselves as an already-trusted client.

PSK recovered in plaintext Trusted session UUID recovered in plaintext

Affected Products

ProductAffected Version
DJI Neo0 – 01.00.0400
DJI Neo 20 – 01.00.0500
DJI Flip0 – 01.00.1200
DJI Air 30 – 01.00.1600
DJI Air 3S0 – 01.00.1400
DJI Avata 20 – 01.00.0400
DJI Avata 3600 – 01.00.0300
DJI Mavic 30 – 01.00.1400
DJI Mavic 3 Classic0 – 01.00.0800
DJI Mavic 3 Pro0 – 01.01.0700
DJI Mavic 4 Pro0 – 01.00.0500
DJI Mini 20 – 01.07.0200
DJI Mini 30 – 01.00.0500
DJI Mini 3 Pro0 – 01.00.0900
DJI Mini 4 Pro0 – 01.00.1100
DJI Mini 5 Pro0 – 01.00.0600

Reproduction

Setup

Capture is done with a Nordic nRF52840 Dongle running the nRF Sniffer for Bluetooth LE firmware. Programmed with that firmware, the dongle acts as a passive sniffer: it follows the advertising and data channels and forwards every received packet to the host over USB serial, where Wireshark decodes it.

  1. Flash the nRF52840 dongle with nRF Sniffer for BLE.
  2. Install the nRF Sniffer Wireshark extcap plugin.
  3. Start Wireshark, select the sniffer interface, and lock onto the drone's BLE address.
  4. Power on the drone and run a normal DJI Fly session (connect, then let the app fetch the Wi-Fi credentials).
  5. Save the captured pcap file in Wireshark after and give it to poc.py.

⚠️ Disclaimer

⚠️ WARNING: This proof of concept is intended strictly for educational, security-research, and authorized penetration-testing purposes.

⚠️ Do NOT use this POC against any aircraft, device, network, or system that you do not own or do not have explicit authorization to test.

Scarica lo strumento