Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2026-77812 — Proof-of-concept that passively sniffs cleartext BLE DUML traffic from DJI drones to recover Wi-Fi PSK and trusted session UUIDs, demonstrating CVE-2026-77812. | Kitploit
ツール/GitHubGitHub/wh02m1/cve-2026-77812
Packet Sniffing & AnalysisBluetooth SecurityVulnerability AnalysisExploitationInformation GatheringWireless SecurityHardware & IoT Security
GitHubwh02m1/cve-2026-77812

CVE-2026-77812

Proof-of-concept that passively sniffs cleartext BLE DUML traffic from DJI drones to recover Wi-Fi PSK and trusted session UUIDs, demonstrating CVE-2026-77812.

リポジトリを見る
18日前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
要求された言語のコンテンツは利用できません。英語版を表示しています。

CVE-2026-77812 — DJI Drone Cleartext BLE Transmission of Wi-Fi PSK and Session UUID POC

CVE-2026-77812

CVE record: https://www.cve.org/CVERecord?id=CVE-2026-77812

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-77812

image

Description

DJI Drone expose a DUML control channel over Bluetooth. Every message on that channel — in both directions, between the DJI Fly app and the drone — is sent in the clear. No BLE link-layer encryption and no application-layer encryption are applied.

A passive attacker within radio range can read the full contents of every command and response, including:

  • the Wi-Fi SSID of the drone's access point,
  • the Wi-Fi PSK, returned by the drone in response to the GET Password command,
  • the trusted session UUID the app registers with the drone.

No pairing, no interaction with the drone, and no prior trust relationship are required. Recovering the PSK lets the attacker join the drone's Wi-Fi network; recovering the UUID lets them present themselves as an already-trusted client.

PSK recovered in plaintext Trusted session UUID recovered in plaintext

Affected Products

ProductAffected Version
DJI Neo0 – 01.00.0400
DJI Neo 20 – 01.00.0500
DJI Flip0 – 01.00.1200
DJI Air 30 – 01.00.1600
DJI Air 3S0 – 01.00.1400
DJI Avata 20 – 01.00.0400
DJI Avata 3600 – 01.00.0300
DJI Mavic 30 – 01.00.1400
DJI Mavic 3 Classic0 – 01.00.0800
DJI Mavic 3 Pro0 – 01.01.0700
DJI Mavic 4 Pro0 – 01.00.0500
DJI Mini 20 – 01.07.0200
DJI Mini 30 – 01.00.0500
DJI Mini 3 Pro0 – 01.00.0900
DJI Mini 4 Pro0 – 01.00.1100
DJI Mini 5 Pro0 – 01.00.0600

Reproduction

Setup

Capture is done with a Nordic nRF52840 Dongle running the nRF Sniffer for Bluetooth LE firmware. Programmed with that firmware, the dongle acts as a passive sniffer: it follows the advertising and data channels and forwards every received packet to the host over USB serial, where Wireshark decodes it.

  1. Flash the nRF52840 dongle with nRF Sniffer for BLE.
  2. Install the nRF Sniffer Wireshark extcap plugin.
  3. Start Wireshark, select the sniffer interface, and lock onto the drone's BLE address.
  4. Power on the drone and run a normal DJI Fly session (connect, then let the app fetch the Wi-Fi credentials).
  5. Save the captured pcap file in Wireshark after and give it to poc.py.

⚠️ Disclaimer

⚠️ WARNING: This proof of concept is intended strictly for educational, security-research, and authorized penetration-testing purposes.

⚠️ Do NOT use this POC against any aircraft, device, network, or system that you do not own or do not have explicit authorization to test.

ツールをダウンロード