CVE-2026-78251: CWE-798 Use of Hard-coded Credentials in DJI Neo
DJI drones contain an FTP service with hardcoded credentials that allow authenticated users to upload unlimited files to a specific directory, potentially exhausting storage and disrupting flight data recording and firmware updates. This affects multiple DJI drone models up to specified firmware versions. Remediation requires a firmware update from DJI.
AI Analysis
Technical Summary
CVE-2026-78251 describes a vulnerability in DJI drones where an FTP service uses hardcoded credentials shared across affected models. Authenticated users can upload files without restrictions to the /blackbox/upgrade/ directory, including overwriting existing files. This can exhaust storage, preventing the drone from writing flight records, logs, telemetry, and potentially blocking firmware updates. Uploaded files persist across reboot and factory reset. Affected models include DJI Neo, Neo 2, Flip, Air 3, Air 3S, Avata 2, Avata 360, Mavic 3 series, Mini 2, Mini 3 series, Mini 4 Pro, and Mini 5 Pro up to specific firmware versions. The vulnerability requires a firmware update for remediation.
Potential Impact
An attacker with access to the drone's internal network or USB RNDIS interface can authenticate using hardcoded credentials to upload unlimited files to the drone's storage, exhausting available space. This prevents the drone from recording flight data and logs, and may block firmware updates, potentially degrading operational reliability and maintenance.
Mitigation Recommendations
Remediation requires a firmware update from DJI. Patch status is not yet confirmed—check the vendor advisory for current remediation guidance.
CVE-2026-78251: CWE-798 Use of Hard-coded Credentials in DJI Neo
Description
DJI drones contain an FTP service with hardcoded credentials that allow authenticated users to upload unlimited files to a specific directory, potentially exhausting storage and disrupting flight data recording and firmware updates. This affects multiple DJI drone models up to specified firmware versions. Remediation requires a firmware update from DJI.
CVSS v4.0
Score 9.3critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-78251 describes a vulnerability in DJI drones where an FTP service uses hardcoded credentials shared across affected models. Authenticated users can upload files without restrictions to the /blackbox/upgrade/ directory, including overwriting existing files. This can exhaust storage, preventing the drone from writing flight records, logs, telemetry, and potentially blocking firmware updates. Uploaded files persist across reboot and factory reset. Affected models include DJI Neo, Neo 2, Flip, Air 3, Air 3S, Avata 2, Avata 360, Mavic 3 series, Mini 2, Mini 3 series, Mini 4 Pro, and Mini 5 Pro up to specific firmware versions. The vulnerability requires a firmware update for remediation.
Potential Impact
An attacker with access to the drone's internal network or USB RNDIS interface can authenticate using hardcoded credentials to upload unlimited files to the drone's storage, exhausting available space. This prevents the drone from recording flight data and logs, and may block firmware updates, potentially degrading operational reliability and maintenance.
Mitigation Recommendations
Remediation requires a firmware update from DJI. Patch status is not yet confirmed—check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CIRCL
- Date Reserved
- 2026-08-24T07:02:39.767Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a8bf150acd9273b4922efce
Added to database: 08/24/2026, 07:22:56 UTC
Last enriched: 08/24/2026, 07:37:06 UTC
Last updated: 08/24/2026, 07:37:06 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.