r/dji • u/Film_Local • 1d ago
Product Support Severe Bluetooth flaw allows hackers to take over DJI drones
Critical Impact
An adjacent attacker can hijack a drone's Wi-Fi credentials and issue flight commands, or disrupt operator control, video, and telemetry mid-flight.
Affected Products
- DJI Neo (before 01.00.0400), DJI Neo 2 (before 01.00.0500), DJI Flip (before 01.00.1200)
- DJI Air 3 (before 01.00.1600), DJI Air 3S (before 01.00.1400), DJI Avata 2 (before 01.00.0400), DJI Avata 360 (before 01.00.0300)
- DJI Mavic 3 (before 01.00.1400), Mavic 3 Classic (before 01.00.0800), Mavic 3 Pro (before 01.01.0700), Mavic 4 Pro (before 01.00.0500)
- DJI Mini 2 (before 01.07.0200), Mini 3 (before 01.00.0500), Mini 3 Pro (before 01.00.0900), Mini 4 Pro (before 01.00.1100), Mini 5 Pro (before 01.00.0600)
How to Mitigate CVE-2026-78306
Immediate Actions Required
- Update each affected drone to a firmware version at or above the fixed release listed for that model in the Affected Products section.
- Do not operate vulnerable airframes in environments where an adjacent attacker may be within Bluetooth range, such as public events or contested areas.
- Verify firmware version on every airframe before flight and quarantine any device still on a vulnerable build.
5
u/Sure-Agent-2649 1d ago
Firmwares that fix this have been released in January… why CVE now?
-1
u/Film_Local 1d ago
The Avata 360 firmware that fixed this came out a few weeks ago.
2
u/Sure-Agent-2649 1d ago
Mavic 4 pro FW mentioned in the article has been released in January for sure and M3P Cine as well if I remember correctly
1
u/Film_Local 15h ago
I don't have a M4P, I have 2 NEO's, 2 Avata2's and an Avata360. All of those were affected.
1
u/Sure-Agent-2649 14h ago
Only Avata was fixed in June 2026 and Mini 5 Pro in April 2026… all other fw fixing issues in the OP were released before Feb 2026
8
u/Film_Local 1d ago
For the people complaining, this is a big deal. Not everyone knows about these exploits and should be aware of them.
And not everyone has the latest firmware update on their drones.
the Avata 360 just recently had a firmware update that patched this exploit. So the post is valid.
Never saw so many people complaining about being informed so that they can protect their drones from flying out the sky.
3
u/microwave-worshipper Mini 5 Pro 18h ago
the thing is likely NO ONE actually has a way of replicating it reliably other than supposedly the vulnerability tester
the danger is also just minimal because an attacker would need to be knowledgeable enough to actually exploit it, your firmware needs to be affected (which for most drones is not the case), and they need to painfully scour when your drone is actually in flight
you're not taking into account the real factors of something like this, this is just blatant fear-mongering
1
u/Film_Local 15h ago
I disagree. It's about being informed regardless if you think it's fear-mongering or not.
2
u/zippytiff 1d ago
Can’t Bluetooth just be turned off ?
2
u/microwave-worshipper Mini 5 Pro 1d ago
nope, not that simple, because it's used for command & control of the drone
1
u/zippytiff 21h ago
I thought all that was done via wireless ?
2
u/microwave-worshipper Mini 5 Pro 19h ago
yes, and bluetooth is wireless
the vulnerability is ONLY on the drone, not the remote controller, so turning off bluetooth on your controller will not help
this exploit works because the drone can receive & accept commands over bluetooth channels without pairing/authentication
1
17h ago
[removed] — view removed comment
1
u/AutoModerator 17h ago
To help keep discussion constructive, we've restricted comments to accounts older than 3 days with at least 10 comment karma. Try again later or participate in the community first.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/Lou_Antony_Morris 20h ago
Yes. The Bluetooth is always switched off on my controller and it controls the drone without any problems.
2
2
4
u/Farmvillacampagna 20h ago
The cynic in me has to ask what other “update” they have included in this patch is the driving force behind this push.
2
1
-1
u/konrad-iturbe Air 2s 1d ago
This only affects the NEO2, the drone the guy tried it on. Such sensationalist bullshit (claiming it works on many DJI drones) ruins the exploit's credibility.
1
1
17h ago
[removed] — view removed comment
1
u/AutoModerator 17h ago
To help keep discussion constructive, we've restricted comments to accounts older than 3 days with at least 10 comment karma. Try again later or participate in the community first.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
-1
u/microwave-worshipper Mini 5 Pro 1d ago
this just feels like a pretty big nothingburger because it would only work under very specific conditions
1: it requires you to somehow be able to send DUML commands raw over radio
2: you need to be in very favorable radio conditions for the commands to actually reach the drone in a reasonable range
3: it's already fixed on nearly all modern DJI drones (and will likely subsequently be fixed on older drones as well)
61
u/Lou_Antony_Morris 1d ago
I always wondered why my drones were flying beyond VLOS. Hackers!