« Volver al listado

DJI

DJI Mini 3 PRO: vulnerabilidades y CVE

DJI Mini 3 PRO tiene 12 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses5
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-78251Crítica (9.3)0.41%—27 ago 2026
DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in…
CVE-2026-78321Media (6)0.24%—24 ago 2026
The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by…
CVE-2026-78306Alta (8.5)0.23%—24 ago 2026
DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory…
CVE-2026-78255Alta (8.7)0.41%—24 ago 2026
The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a predictable pattern, allowing an attacker who joins…
CVE-2026-77812Crítica (9.4)0.09%—21 ago 2026
DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to…
CVE-2023-6951Media (6.6)0.29%—2 abr 2024
A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the WPA2 PSK key and authenticate without permission to the drone’s Wi- Fi…
CVE-2023-6948Baja (3)0.21%—2 abr 2024
A Buffer Copy without Checking Size of Input issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payload…
CVE-2023-51456Media (6.8)0.24%—2 abr 2024
A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to trigger an out-of-bound read/write into the process memory through a…
CVE-2023-51455Media (6.8)0.24%—2 abr 2024
A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to corrupt a controlled memory location due to a missing input…
CVE-2023-51454Media (6.8)0.25%—2 abr 2024
A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to overwrite a pointer in the process memory through a crafted payload triggering…
CVE-2023-51453Baja (3)0.21%—2 abr 2024
A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payload triggering a…
CVE-2023-51452Baja (3)0.21%—2 abr 2024
A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payload triggering a…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1210 Exploitation of Remote Services2
  3. T1005 Data from Local System1
  4. T1078 Valid Accounts1
  5. T1078.001 Default Accounts1
  6. T1212 Exploitation for Credential Access1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de DJI