PatchSiren

DJI CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL DJI CVE published 2026-08-21

CVE-2026-77812

CVE-2026-77812 involves DJI drones transmitting DUML protocol messages over BLE without encryption. An attacker within BLE range can passively sniff this traffic and recover Wi-Fi credentials in cleartext, including the drone's Wi-Fi PSK, SSID, and trusted identifier UUID. This allows the attacker to join the drone's internal Wi-Fi network, interact with network services, and decrypt Wi-Fi traffic. The af [truncated]