Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-77812 — Proof-of-concept that passively sniffs cleartext BLE DUML traffic from DJI drones to recover Wi-Fi PSK and trusted session UUIDs, demonstrating CVE-2026-77812. | Kitploit
도구/GitHubGitHub/wh02m1/cve-2026-77812
Packet Sniffing & AnalysisBluetooth SecurityVulnerability AnalysisExploitationInformation GatheringWireless SecurityHardware & IoT Security
GitHubwh02m1/cve-2026-77812

CVE-2026-77812

Proof-of-concept that passively sniffs cleartext BLE DUML traffic from DJI drones to recover Wi-Fi PSK and trusted session UUIDs, demonstrating CVE-2026-77812.

저장소 보기
18일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

CVE-2026-77812 — DJI Drone Cleartext BLE Transmission of Wi-Fi PSK and Session UUID POC

CVE-2026-77812

CVE record: https://www.cve.org/CVERecord?id=CVE-2026-77812

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-77812

image

Description

DJI Drone expose a DUML control channel over Bluetooth. Every message on that channel — in both directions, between the DJI Fly app and the drone — is sent in the clear. No BLE link-layer encryption and no application-layer encryption are applied.

A passive attacker within radio range can read the full contents of every command and response, including:

  • the Wi-Fi SSID of the drone's access point,
  • the Wi-Fi PSK, returned by the drone in response to the GET Password command,
  • the trusted session UUID the app registers with the drone.

No pairing, no interaction with the drone, and no prior trust relationship are required. Recovering the PSK lets the attacker join the drone's Wi-Fi network; recovering the UUID lets them present themselves as an already-trusted client.

PSK recovered in plaintext Trusted session UUID recovered in plaintext

Affected Products

ProductAffected Version
DJI Neo0 – 01.00.0400
DJI Neo 20 – 01.00.0500
DJI Flip0 – 01.00.1200
DJI Air 30 – 01.00.1600
DJI Air 3S0 – 01.00.1400
DJI Avata 20 – 01.00.0400
DJI Avata 3600 – 01.00.0300
DJI Mavic 30 – 01.00.1400
DJI Mavic 3 Classic0 – 01.00.0800
DJI Mavic 3 Pro0 – 01.01.0700
DJI Mavic 4 Pro0 – 01.00.0500
DJI Mini 20 – 01.07.0200
DJI Mini 30 – 01.00.0500
DJI Mini 3 Pro0 – 01.00.0900
DJI Mini 4 Pro0 – 01.00.1100
DJI Mini 5 Pro0 – 01.00.0600

Reproduction

Setup

Capture is done with a Nordic nRF52840 Dongle running the nRF Sniffer for Bluetooth LE firmware. Programmed with that firmware, the dongle acts as a passive sniffer: it follows the advertising and data channels and forwards every received packet to the host over USB serial, where Wireshark decodes it.

  1. Flash the nRF52840 dongle with nRF Sniffer for BLE.
  2. Install the nRF Sniffer Wireshark extcap plugin.
  3. Start Wireshark, select the sniffer interface, and lock onto the drone's BLE address.
  4. Power on the drone and run a normal DJI Fly session (connect, then let the app fetch the Wi-Fi credentials).
  5. Save the captured pcap file in Wireshark after and give it to poc.py.

⚠️ Disclaimer

⚠️ WARNING: This proof of concept is intended strictly for educational, security-research, and authorized penetration-testing purposes.

⚠️ Do NOT use this POC against any aircraft, device, network, or system that you do not own or do not have explicit authorization to test.

도구 다운로드