VYPR

DJI Mini 2

by Dji

CVEs (2)

  • CVE-2026-78306HigAug 24, 2026
    risk 0.55cvss —epss 0.00

    DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the…

  • CVE-2026-78321MedAug 24, 2026
    risk 0.39cvss —epss 0.00

    The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media file, preventing the server…