PatchSiren cyber security CVE debrief
CVE-2026-77812 DJI CVE debrief
CVE-2026-77812 involves DJI drones transmitting DUML protocol messages over BLE without encryption. An attacker within BLE range can passively sniff this traffic and recover Wi-Fi credentials in cleartext, including the drone's Wi-Fi PSK, SSID, and trusted identifier UUID. This allows the attacker to join the drone's internal Wi-Fi network, interact with network services, and decrypt Wi-Fi traffic. The affected models include DJI Neo, DJI Neo 2, DJI Flip, DJI Air 3, DJI Air 3S, DJI Avata 2, DJI Avata 360, DJI Mavic 3, DJI Mavic 3 Classic, DJI Mavic 3 Pro, DJI Mavic 4 Pro, DJI Mini 2, DJI Mini 3, DJI Mini 3 Pro, DJI Mini 4 Pro, and DJI Mini 5 Pro. The vulnerability is rated as CRITICAL with a CVSS score of 9.4. Remediation requires a firmware update from the vendor.
- Vendor
- DJI
- Product
- DJI Neo
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Organizations and individuals using affected DJI drone models should apply firmware updates from the vendor to remediate the vulnerability. Additionally, users should be aware of the potential risks associated with using these drones and take necessary precautions to secure their Wi-Fi networks.
Technical summary
CVE-2026-77812 involves DJI drones transmitting DUML protocol messages over BLE without encryption. An attacker within BLE range can passively sniff this traffic and recover Wi-Fi credentials in cleartext, including the drone's Wi-Fi PSK, SSID, and trusted identifier UUID. This allows the attacker to join the drone's internal Wi-Fi network, interact with network services, and decrypt Wi-Fi traffic.
Defensive priority
CVE-2026-77812 is rated as CRITICAL with a CVSS score of 9.4. Affected models include DJI Neo, DJI Neo 2, DJI Flip, DJI Air 3, DJI Air 3S, DJI Avata 2, DJI Avata 360, DJI Mavic 3, DJI Mavic 3 Classic, DJI Mavic 3 Pro, DJI Mavic 4 Pro, DJI Mini 2, DJI Mini 3, DJI Mini 3 Pro, DJI Mini 4 Pro, and DJI Mini 5 Pro. Remediation requires a firmware update from the vendor.
Recommended defensive actions
- Apply firmware updates from the vendor
- Inventory affected DJI drone models
- Monitor for BLE sniffing attempts
- Implement compensating controls for Wi-Fi network access
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE-2026-77812 details indicate that DJI drones transmit DUML protocol messages over BLE without encryption, allowing an attacker within BLE range to passively sniff traffic and recover Wi-Fi credentials in cleartext. The credentials include the drone's Wi-Fi PSK, SSID, and trusted identifier UUID. Obtaining these credentials enables the attacker to join the drone's internal Wi-Fi network, interact with network services, and decrypt Wi-Fi traffic.
Official resources
-
CVE-2026-77812 CVE record
CVE.org
-
CVE-2026-77812 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
5a6e4751-2f3f-4070-9419-94fb35b644e8
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:47.557Z and has not been modified since then.