CVE-2026-78251: CWE-798 Use of Hard-coded Credentials in DJI Neo
Description
DJI drones contain an FTP service with hardcoded credentials that allow authenticated users to upload unlimited files to the /blackbox/upgrade/ directory, including overwriting existing files. This can lead to exhaustion of storage, preventing the drone from recording flight data and potentially blocking firmware updates. The vulnerability affects multiple DJI drone models with firmware versions prior to specified updates. Remediation requires a firmware update from DJI.
CVSS v4.0
Score 9.3critical
Affected software
DJI
Neo
DJI
Neo 2
DJI
Flip
DJI
Air 3
DJI
Air 3S
DJI
Avata 2
DJI
Avata 360
DJI
Mavic 3
DJI
Mavic 3 Classic
DJI
Mavic 3 Pro
DJI
Mavic 4 Pro
DJI
Mini 2
DJI
Mini 3
DJI
Mini 3 Pro
DJI
Mini 4 Pro
DJI
Mini 5 Pro
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-78251 is a vulnerability in DJI drones where an FTP service uses hardcoded credentials shared across affected models. Authenticated users can upload unlimited files without restrictions on size or count to the /blackbox/upgrade/ directory and overwrite existing files. An attacker with access to the drone's internal network or USB RNDIS interface can exploit this to exhaust storage, disrupting flight record logging and firmware updates. The uploaded files persist through reboot and factory reset. Affected models include DJI Neo, Neo 2, Flip, Air 3, Air 3S, Avata 2, Avata 360, Mavic 3 series, Mini 2, Mini 3 series, Mini 4 Pro, and Mini 5 Pro with firmware versions prior to specified thresholds. A firmware update from DJI is required for remediation.
Potential Impact
An attacker with network or USB interface access can use hardcoded FTP credentials to upload unlimited files, exhausting storage space on the drone. This prevents the drone from writing flight records, logs, and telemetry data, and may block subsequent firmware updates. Persistence of uploaded files across reboot and factory reset increases the impact. This can degrade drone functionality and maintenance.
Mitigation Recommendations
Remediation requires applying a firmware update from DJI. No official patch or workaround is currently documented. Users should monitor DJI advisories for firmware updates addressing this issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CIRCL
- Date Reserved
- 2026-08-24T07:02:39.767Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8bf150acd9273b4922efce
Added to database: 08/24/2026, 07:22:56 UTC
Last enriched: 09/10/2026, 12:22:53 UTC
Last updated: 10/08/2026, 18:48:48 UTC
Views: 226
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.