Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.41% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 27/8/2026 | 28/8/2026 | DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in that directory. An attacker with access to… | |
| Aplazada | Media (6) | 0.24% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 24/8/2026 | 26/8/2026 | The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media file, preventing the server from handling legitimate requests and… | |
| Aplazada | Alta (8.5) | 0.23% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 24/8/2026 | 26/8/2026 | DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect… | |
| Aplazada | Alta (8.7) | 0.41% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 24/8/2026 | 26/8/2026 | The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a predictable pattern, allowing an attacker who joins the drone's internal network to enumerate valid filenames and exfiltrate stored photos and videos.… | |
| Aplazada | Crítica (9.4) | 0.09% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 21/8/2026 | 26/8/2026 | DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to QuickTransfer mode, the DJI Fly application exchanges DUML messages with the drone over BLE,… |