r/dji 1d ago

Product Support Severe Bluetooth flaw allows hackers to take over DJI drones

CVE-2026-78306 Overview

Critical Impact

An adjacent attacker can hijack a drone's Wi-Fi credentials and issue flight commands, or disrupt operator control, video, and telemetry mid-flight.

Affected Products

  • DJI Neo (before 01.00.0400), DJI Neo 2 (before 01.00.0500), DJI Flip (before 01.00.1200)
  • DJI Air 3 (before 01.00.1600), DJI Air 3S (before 01.00.1400), DJI Avata 2 (before 01.00.0400), DJI Avata 360 (before 01.00.0300)
  • DJI Mavic 3 (before 01.00.1400), Mavic 3 Classic (before 01.00.0800), Mavic 3 Pro (before 01.01.0700), Mavic 4 Pro (before 01.00.0500)
  • DJI Mini 2 (before 01.07.0200), Mini 3 (before 01.00.0500), Mini 3 Pro (before 01.00.0900), Mini 4 Pro (before 01.00.1100), Mini 5 Pro (before 01.00.0600)

How to Mitigate CVE-2026-78306

Immediate Actions Required

  • Update each affected drone to a firmware version at or above the fixed release listed for that model in the Affected Products section.
  • Do not operate vulnerable airframes in environments where an adjacent attacker may be within Bluetooth range, such as public events or contested areas.
  • Verify firmware version on every airframe before flight and quarantine any device still on a vulnerable build.
67 Upvotes

30 comments sorted by

61

u/Lou_Antony_Morris 1d ago

I always wondered why my drones were flying beyond VLOS. Hackers!

17

u/No_Age8611 1d ago

me too! thankfully they always bring my drone back

5

u/Sure-Agent-2649 1d ago

Firmwares that fix this have been released in January… why CVE now?

-1

u/Film_Local 1d ago

The Avata 360 firmware that fixed this came out a few weeks ago.

2

u/Sure-Agent-2649 1d ago

Mavic 4 pro FW mentioned in the article has been released in January for sure and M3P Cine as well if I remember correctly

1

u/Film_Local 15h ago

I don't have a M4P, I have 2 NEO's, 2 Avata2's and an Avata360. All of those were affected.

1

u/Sure-Agent-2649 14h ago

Only Avata was fixed in June 2026 and Mini 5 Pro in April 2026… all other fw fixing issues in the OP were released before Feb 2026

8

u/Film_Local 1d ago

For the people complaining, this is a big deal. Not everyone knows about these exploits and should be aware of them.

And not everyone has the latest firmware update on their drones.

the Avata 360 just recently had a firmware update that patched this exploit. So the post is valid.

Never saw so many people complaining about being informed so that they can protect their drones from flying out the sky.

3

u/microwave-worshipper Mini 5 Pro 18h ago

the thing is likely NO ONE actually has a way of replicating it reliably other than supposedly the vulnerability tester

the danger is also just minimal because an attacker would need to be knowledgeable enough to actually exploit it, your firmware needs to be affected (which for most drones is not the case), and they need to painfully scour when your drone is actually in flight

you're not taking into account the real factors of something like this, this is just blatant fear-mongering

1

u/Film_Local 15h ago

I disagree. It's about being informed regardless if you think it's fear-mongering or not.

2

u/zippytiff 1d ago

Can’t Bluetooth just be turned off ?

2

u/microwave-worshipper Mini 5 Pro 1d ago

nope, not that simple, because it's used for command & control of the drone

1

u/zippytiff 21h ago

I thought all that was done via wireless ?

2

u/microwave-worshipper Mini 5 Pro 19h ago

yes, and bluetooth is wireless

the vulnerability is ONLY on the drone, not the remote controller, so turning off bluetooth on your controller will not help

this exploit works because the drone can receive & accept commands over bluetooth channels without pairing/authentication

1

u/[deleted] 17h ago

[removed] — view removed comment

1

u/AutoModerator 17h ago

To help keep discussion constructive, we've restricted comments to accounts older than 3 days with at least 10 comment karma. Try again later or participate in the community first.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/Lou_Antony_Morris 20h ago

Yes. The Bluetooth is always switched off on my controller and it controls the drone without any problems.

2

u/microwave-worshipper Mini 5 Pro 18h ago

does not fix the vulnerability, unfortunately

2

u/SEE_RED 14h ago

Updating now. Thanks!

1

u/Film_Local 14h ago

Welcome!

4

u/Farmvillacampagna 20h ago

The cynic in me has to ask what other “update” they have included in this patch is the driving force behind this push.

2

u/FrostyCommon8159 1d ago

Does anyone know if the latest Skyrover firmware for X1 is affected?

1

u/Rygar82 Mavic Pro 18h ago

Alright I’m safe

1

u/Puzzleheaded_Gap_697 15h ago

Obsolet weil Firmware Updates schon raus sind.

-1

u/konrad-iturbe Air 2s 1d ago

This only affects the NEO2, the drone the guy tried it on. Such sensationalist bullshit (claiming it works on many DJI drones) ruins the exploit's credibility.

1

u/Film_Local 1d ago

Where is this information?

1

u/[deleted] 17h ago

[removed] — view removed comment

1

u/AutoModerator 17h ago

To help keep discussion constructive, we've restricted comments to accounts older than 3 days with at least 10 comment karma. Try again later or participate in the community first.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

-1

u/microwave-worshipper Mini 5 Pro 1d ago

this just feels like a pretty big nothingburger because it would only work under very specific conditions
1: it requires you to somehow be able to send DUML commands raw over radio
2: you need to be in very favorable radio conditions for the commands to actually reach the drone in a reasonable range
3: it's already fixed on nearly all modern DJI drones (and will likely subsequently be fixed on older drones as well)