
Proof-of-concept exploiting DJI drone Bluetooth DUML command injection, sending unauthenticated commands to read credentials, alter Wi-Fi config, and control aircraft systems.
CVE record: https://www.cve.org/CVERecord?id=CVE-2026-78306
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-78306
DJI drones expose a Bluetooth interface used to establish a connection to the drone's Wi-Fi interface and exchange Wi-Fi credentials
The Bluetooth interface checks the device's trusted UUID for three commands:
The remaining commands do not require the same authentication check. As a result, a remote attacker within Bluetooth range may be able to send unauthorized DUML commands to the drone.
Depending on the command, an attacker may be able to modify the drone's configuration, including changing the Wi-Fi password and potentially gaining access to the drone's internal network; enabling or disabling radio interfaces; restarting or powering off the aircraft; resetting the configuration, which wipes all videos and pictures captured by the drone; and performing other actions.
Note: The exploit currently works in-flight when controlling the drone over Wi-Fi, and on the ground/when drone land when controlling the drone over radio.
| Product | Affected Version |
|---|---|
| DJI Neo | 0 – 01.00.0400 |
| DJI Neo 2 | 0 – 01.00.0500 |
| DJI Flip | 0 – 01.00.1200 |
| DJI Air 3 | 0 – 01.00.1600 |
| DJI Air 3S | 0 – 01.00.1400 |
| DJI Avata 2 | 0 – 01.00.0400 |
| DJI Avata 360 | 0 – 01.00.0300 |
| DJI Mavic 3 | 0 – 01.00.1400 |
| DJI Mavic 3 Classic | 0 – 01.00.0800 |
| DJI Mavic 3 Pro | 0 – 01.01.0700 |
| DJI Mavic 4 Pro | 0 – 01.00.0500 |
| DJI Mini 2 | 0 – 01.07.0200 |
| DJI Mini 3 | 0 – 01.00.0500 |
| DJI Mini 3 Pro | 0 – 01.00.0900 |
| DJI Mini 4 Pro | 0 – 01.00.1100 |
| DJI Mini 5 Pro | 0 – 01.00.0600 |
https://github.com/user-attachments/assets/57f51df2-5160-404c-9fd3-2a3a8b700008
# Clone the repository
git clone https://github.com/Wh02m1/CVE-2026-78306.git
cd CVE-2026-78306-POC
# Create and activate a Python virtual environment
python3 -m venv venv
source venv/bin/activate
# Install dependencies
pip install -r requirements.txt
python3 ble_console.py
The following commands are registered in commands.json and are generated directly from it. Commands marked danger require explicit confirmation before being sent.
| Command | What it does |
|---|---|
| GET WiFi SSID [AUTH] | Retrieves the configured Wi-Fi SSID. Requires a trusted UUID. |
| GET WiFi Password [AUTH] | Retrieves the Wi-Fi WPA2 pre-shared key. Requires a trusted UUID. |
| GET WiFi MAC address [AUTH] | Retrieves the Wi-Fi AP MAC address. Requires a trusted UUID. |
| GET Country Code | Retrieves the two-letter regulatory country code. |
| GET Channel | Retrieves the currently active Wi-Fi channel. |
| GET Band | Retrieves the configured 2.4/5 GHz band selection. |
| GET RSSI [stub] | Queries the RSSI handler; this build returns a stub value. |
| GET WiFi/BT status | Retrieves the Wi-Fi and Bluetooth radio state. |
| GET Version | Retrieves the firmware version string. |
| Command | What it does |
|---|---|
| SET NEW WiFi SSID | Changes the configured Wi-Fi SSID. |
| SET NEW WiFi Password | Changes the configured Wi-Fi password. |
| SET NEW WiFi MAC Address | Changes the runtime Wi-Fi BSSID configuration. |
| SET NEW Country Code | Changes the configured regulatory country code. |
| SET NEW Country Code Ext | Handles extended country-code configuration. |
| SET NEW Channel | Changes the Wi-Fi channel and causes the AP to restart. |
These operations are classified as danger in the POC and therefore require explicit confirmation before being sent.
| Command | What it does |
|---|---|
| Start WiFi | Starts the Wi-Fi interface. |
| Stop WiFi | Stops the Wi-Fi interface. |
| Restart WiFi + Bluetooth | Restarts the Wi-Fi and Bluetooth radios. |
| Start Bluetooth | Starts the Bluetooth radio. |
| Stop Bluetooth | Stops the Bluetooth radio and terminates the current session. |
| Sysmode power control | Controls the Wi-Fi/Bluetooth radio power state. |
| Command | What it does |
|---|---|
| Factory Reset WIFI | Restores the Wi-Fi configuration to its default state. |
| Factory Restore Params | Restores the network configuration to factory defaults. |
The POC marks both operations as dangerous because they modify persistent configuration.
| Command | What it does |
|---|---|
| Start The Drone FTP server | Starts the aircraft's FTP service. |
| Enable Storage Export | Enables storage export. |
| Disable Storage Export | Disables storage export. |
| reboot The Drone | Reboots the aircraft. |
| poweroff The Drone | Powers off the aircraft (physical access needed to power back on). |
| powersave mode The Drone | Places the aircraft into power-save mode. |
| Command | What it does |
|---|---|
| Start Remote Controller DoS | First step of the remote-controller denial-of-service sequence; puts the aircraft into the state the disconnect step requires. |
| Stop Remote Controller DoS | Completes the sequence: the aircraft stops servicing the controller link, so the remote controller loses the aircraft. Run the first step beforehand. |
| Remote Controller Recover | Attempts to return the aircraft to normal operation. |
| Command | What it does |
|---|---|
| Change a parameter | Changes a drone configuration parameter using its 32-bit name hash. |
| Reset a parameter | Resets a configuration parameter to its firmware default. |
The POC obtains parameter names from flyc_parameters.txt and provides interactive parameter selection. To add a known parameter that you want to modify or reset, add its name to flyc_parameters.txt. The parameter will then be available for selection when the POC is started.
Commands classified as danger require explicit confirmation before transmission.
The confirmation screen displays information such as:
──────────────────────────────────────────────────────────────────────
!!! DANGEROUS COMMAND !!!
──────────────────────────────────────────────────────────────────────
COMMAND Factory Reset WIFI
ROUTE 07/0f → 0x07
PAYLOAD (none)
DOES resets the Wi-Fi config and regenerates the PSK
WARNING Disconnects every device currently on the drone's Wi-Fi.
──────────────────────────────────────────────────────────────────────
Type YES to send:
The Change a parameter function provides access to the known configuration parameters listed in flyc_parameters.txt.
Reset a parameter uses reset_cfg_item to restore the selected parameter to its firmware default.
For a complete list of the extracted parameters and more details, see the FLYC Parameters wiki page.
The POC also provides several predefined macros: