PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77812 DJI CVE debrief

CVE-2026-77812 involves DJI drones transmitting DUML protocol messages over BLE without encryption. An attacker within BLE range can passively sniff this traffic and recover Wi-Fi credentials in cleartext, including the drone's Wi-Fi PSK, SSID, and trusted identifier UUID. This allows the attacker to join the drone's internal Wi-Fi network, interact with network services, and decrypt Wi-Fi traffic. The affected models include DJI Neo, DJI Neo 2, DJI Flip, DJI Air 3, DJI Air 3S, DJI Avata 2, DJI Avata 360, DJI Mavic 3, DJI Mavic 3 Classic, DJI Mavic 3 Pro, DJI Mavic 4 Pro, DJI Mini 2, DJI Mini 3, DJI Mini 3 Pro, DJI Mini 4 Pro, and DJI Mini 5 Pro. The vulnerability is rated as CRITICAL with a CVSS score of 9.4. Remediation requires a firmware update from the vendor.

Vendor
DJI
Product
DJI Neo
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

Organizations and individuals using affected DJI drone models should apply firmware updates from the vendor to remediate the vulnerability. Additionally, users should be aware of the potential risks associated with using these drones and take necessary precautions to secure their Wi-Fi networks.

Technical summary

CVE-2026-77812 involves DJI drones transmitting DUML protocol messages over BLE without encryption. An attacker within BLE range can passively sniff this traffic and recover Wi-Fi credentials in cleartext, including the drone's Wi-Fi PSK, SSID, and trusted identifier UUID. This allows the attacker to join the drone's internal Wi-Fi network, interact with network services, and decrypt Wi-Fi traffic.

Defensive priority

CVE-2026-77812 is rated as CRITICAL with a CVSS score of 9.4. Affected models include DJI Neo, DJI Neo 2, DJI Flip, DJI Air 3, DJI Air 3S, DJI Avata 2, DJI Avata 360, DJI Mavic 3, DJI Mavic 3 Classic, DJI Mavic 3 Pro, DJI Mavic 4 Pro, DJI Mini 2, DJI Mini 3, DJI Mini 3 Pro, DJI Mini 4 Pro, and DJI Mini 5 Pro. Remediation requires a firmware update from the vendor.

Recommended defensive actions

  • Apply firmware updates from the vendor
  • Inventory affected DJI drone models
  • Monitor for BLE sniffing attempts
  • Implement compensating controls for Wi-Fi network access
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE-2026-77812 details indicate that DJI drones transmit DUML protocol messages over BLE without encryption, allowing an attacker within BLE range to passively sniff traffic and recover Wi-Fi credentials in cleartext. The credentials include the drone's Wi-Fi PSK, SSID, and trusted identifier UUID. Obtaining these credentials enables the attacker to join the drone's internal Wi-Fi network, interact with network services, and decrypt Wi-Fi traffic.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:47.557Z and has not been modified since then.