CRITICAL
DJI
CVE published 2026-08-21
CVE-2026-77812
CVE-2026-77812 involves DJI drones transmitting DUML protocol messages over BLE without encryption. An attacker within BLE range can passively sniff this traffic and recover Wi-Fi credentials in cleartext, including the drone's Wi-Fi PSK, SSID, and trusted identifier UUID. This allows the attacker to join the drone's internal Wi-Fi network, interact with network services, and decrypt Wi-Fi traffic. The af [truncated]