Skip to content
KitploitKITPLOIT
ИнструментыЭксплойтыБлог
Log in
Отправить
ИнструментыЭксплойтыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

ЛентыКонтактыКонфиденциальность© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
CVE-2026-77812 — Proof-of-concept that passively sniffs cleartext BLE DUML traffic from DJI drones to recover Wi-Fi PSK and trusted session UUIDs, demonstrating CVE-2026-77812. | Kitploit
Инструменты/GitHubGitHub/wh02m1/cve-2026-77812
Packet Sniffing & AnalysisBluetooth SecurityVulnerability AnalysisExploitationInformation GatheringWireless SecurityHardware & IoT Security
GitHubwh02m1/cve-2026-77812

CVE-2026-77812

Proof-of-concept that passively sniffs cleartext BLE DUML traffic from DJI drones to recover Wi-Fi PSK and trusted session UUIDs, demonstrating CVE-2026-77812.

Репозиторий
18 дней назадЕщё не проверено

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться
Контент недоступен на запрошенном языке. Показываем английскую версию.

CVE-2026-77812 — DJI Drone Cleartext BLE Transmission of Wi-Fi PSK and Session UUID POC

CVE-2026-77812

CVE record: https://www.cve.org/CVERecord?id=CVE-2026-77812

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-77812

image

Description

DJI Drone expose a DUML control channel over Bluetooth. Every message on that channel — in both directions, between the DJI Fly app and the drone — is sent in the clear. No BLE link-layer encryption and no application-layer encryption are applied.

A passive attacker within radio range can read the full contents of every command and response, including:

  • the Wi-Fi SSID of the drone's access point,
  • the Wi-Fi PSK, returned by the drone in response to the GET Password command,
  • the trusted session UUID the app registers with the drone.

No pairing, no interaction with the drone, and no prior trust relationship are required. Recovering the PSK lets the attacker join the drone's Wi-Fi network; recovering the UUID lets them present themselves as an already-trusted client.

PSK recovered in plaintext Trusted session UUID recovered in plaintext

Affected Products

ProductAffected Version
DJI Neo0 – 01.00.0400
DJI Neo 20 – 01.00.0500
DJI Flip0 – 01.00.1200
DJI Air 30 – 01.00.1600
DJI Air 3S0 – 01.00.1400
DJI Avata 20 – 01.00.0400
DJI Avata 3600 – 01.00.0300
DJI Mavic 30 – 01.00.1400
DJI Mavic 3 Classic0 – 01.00.0800
DJI Mavic 3 Pro0 – 01.01.0700
DJI Mavic 4 Pro0 – 01.00.0500
DJI Mini 20 – 01.07.0200
DJI Mini 30 – 01.00.0500
DJI Mini 3 Pro0 – 01.00.0900
DJI Mini 4 Pro0 – 01.00.1100
DJI Mini 5 Pro0 – 01.00.0600

Reproduction

Setup

Capture is done with a Nordic nRF52840 Dongle running the nRF Sniffer for Bluetooth LE firmware. Programmed with that firmware, the dongle acts as a passive sniffer: it follows the advertising and data channels and forwards every received packet to the host over USB serial, where Wireshark decodes it.

  1. Flash the nRF52840 dongle with nRF Sniffer for BLE.
  2. Install the nRF Sniffer Wireshark extcap plugin.
  3. Start Wireshark, select the sniffer interface, and lock onto the drone's BLE address.
  4. Power on the drone and run a normal DJI Fly session (connect, then let the app fetch the Wi-Fi credentials).
  5. Save the captured pcap file in Wireshark after and give it to poc.py.

⚠️ Disclaimer

⚠️ WARNING: This proof of concept is intended strictly for educational, security-research, and authorized penetration-testing purposes.

⚠️ Do NOT use this POC against any aircraft, device, network, or system that you do not own or do not have explicit authorization to test.

Скачать инструмент