DJI
DJI Mini 4 PRO: vulnerabilities and CVEs
DJI Mini 4 PRO has 5 published vulnerabilities, 5 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs5
Last 12 months5
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-78251 | Critical (9.3) | 0.41% | — | Aug 27, 2026 | DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in… |
| CVE-2026-78321 | Medium (6) | 0.24% | — | Aug 24, 2026 | The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by… |
| CVE-2026-78306 | High (8.5) | 0.23% | — | Aug 24, 2026 | DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory… |
| CVE-2026-78255 | High (8.7) | 0.41% | — | Aug 24, 2026 | The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a predictable pattern, allowing an attacker who joins… |
| CVE-2026-77812 | Critical (9.4) | 0.09% | — | Aug 21, 2026 | DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.