Skip to main content
flight_takeoff Drone Ranker

DJI Bluetooth Vulnerability: 16 Models at Risk, What Pilots Should Do

alihan
6 Min Read
DJI Bluetooth Vulnerability: 16 Models at Risk, What Pilots Should Do

DJI Bluetooth vulnerability CVE-2026-78306 is back in the headlines after a 21 September report described how a nearby attacker could send unauthenticated commands to affected aircraft. The public vulnerability record dates to 24 August 2026; this is renewed coverage, not a newly discovered flaw today. The record names 16 DJI models across the Neo, Flip, Air, Avata, Mavic and Mini families. It describes changes to wireless settings and possible loss of connectivity. A complete mid-air takeover has not been demonstrated in the cited reporting.

For owners, the immediate question is simple: is your exact model and firmware in the published list, and is an update available through DJI? Here is what the records establish, what remains unproven, and what to check before your next flight.

What the DJI Bluetooth vulnerability record says

Researchers Abdelrahman Yousef and Jordan Samhi reported an unauthenticated DJI Universal Markup Language (DUML) command interface over Bluetooth. The CVE-2026-78306 advisory says a person within Bluetooth range could change Wi-Fi configuration parameters or interrupt Wi-Fi and Bluetooth connections. This can disrupt a wireless link used for control, video or telemetry. The advisory rates the issue High, 8.5/10 under CVSS 4.0.

The record also describes a possible path from altered Wi-Fi credentials to the drone’s internal network and then potentially to flight-control functions. That is a potential impact, not proof that a researcher took over an aircraft in flight. Cybernews’ 21 September report explicitly says its cited proof of concept did not demonstrate mid-air takeover. Its report also found no publicly reported exploitation in the wild. We have not independently tested the vulnerability.

DJI Bluetooth vulnerability: affected models and firmware

The DJI Bluetooth vulnerability table below reproduces the model names and firmware boundaries in the public CVE description. These are versions named as affected in that record, not a verified list of fixed releases. A model’s presence here does not mean every aircraft currently in use runs affected firmware. Check the version installed on your own device and DJI’s current update prompt.

DJI modelFirmware boundary named in CVE
Neo01.00.0400
Neo 201.00.0500
Flip01.00.1200
Air 301.00.1600
Air 3S01.00.1400
Avata 201.00.0400
Avata 36001.00.0300
Mavic 301.00.1400
Mavic 3 Classic01.00.0800
Mavic 3 Pro01.01.0700
Mavic 4 Pro01.00.0500
Mini 201.07.0200
Mini 301.00.0500
Mini 3 Pro01.00.0900
Mini 4 Pro01.00.1100
Mini 5 Pro01.00.0600

For context on two popular aircraft in the list, see our DJI Flip vs DJI Mini 4 Pro comparison, Flip analysis and Mini 4 Pro review. Those buying guides compare camera and flight features; the security assessment here depends on the firmware installed on an individual drone.

DJI Bluetooth vulnerability: can attackers take over a drone mid-flight?

Not as an established outcome of this research. The public advisory describes a possible route to the internal Wi-Fi network and potential flight-control access. It also describes commands that can interrupt connections. The latter is a concrete concern for pilots, because loss of a link during flight is operationally significant. But the cited proof of concept did not show a completed in-flight takeover, and the reports do not establish that attacks are occurring in the wild.

The attack is also described as adjacent: the actor needs to be within Bluetooth range of an affected aircraft. It is not a claim that anyone anywhere on the internet can remotely commandeer a DJI drone. Range, aircraft state, firmware and connection mode matter.

A separate DJI Bluetooth vulnerability concerns credentials

Do not confuse CVE-2026-78306 with CVE-2026-77812, published on 21 August. That separate record says Bluetooth Low Energy exchanges can expose Wi-Fi credentials and a trusted-client identifier to a nearby passive observer during certain connection or QuickTransfer activity. One finding concerns unauthenticated commands; the other concerns unencrypted data. They are related in topic but have distinct mechanisms and severity scores.

What should DJI owners do now?

  1. Identify the exact model and installed firmware. Check the aircraft’s information screen in the DJI app and compare it with the published record. Do not infer your version from the purchase date.
  2. Check DJI’s official update path. DJI’s firmware guide explains updates through the DJI app or DJI Assistant 2, depending on the model. Follow the prompts for the aircraft and controller, then confirm the installed version.
  3. Update in a controlled setting before flight. Keep adequate battery charge and do not interrupt the process. If an update is unavailable or fails, contact DJI Support rather than assuming a version number in the CVE is a confirmed fixed release.
  4. Plan for link loss as a flight risk. Keep a safe return margin and follow the normal preflight checks and local rules. Avoid treating Bluetooth proximity or QuickTransfer as a substitute for a verified firmware remedy.

DJI’s general update instructions are not a model-by-model security bulletin for these CVEs. As of this 22 September review, the public advisory itself does not identify a definitive patched version for every named aircraft. We will update this article if DJI publishes a specific fix matrix or the researchers demonstrate additional impact.

DJI Bluetooth vulnerability: quick answers

Is every DJI drone affected?

No. The CVE names 16 models and particular firmware boundaries. It does not describe every DJI product or prove that each current aircraft runs an affected release.

Is the Bluetooth problem new today?

No. CVE-2026-78306 was published in August 2026. A 21 September report brought the finding back into the news cycle; the date of that report should not be mistaken for the original disclosure date.

Can a firmware update fix it?

The advisory says vendor firmware is required to remediate the issue. Check DJI’s official updater for your model. The public records cited here do not justify claiming that a particular version is patched unless DJI confirms it.

Sources and editorial method

This article is based on the researcher’s CVE list, the public CVE-2026-78306 record, the separate CVE-2026-77812 record, DJI’s firmware guidance and Cybernews’ 21 September reporting. We have not performed penetration testing or verified a DJI patch independently. Source status checked 22 September 2026.

fact_check

Sources

Primary references used for factual claims in this article.

All News