CVE-2026-78306 is a missing-authentication vulnerability in the Bluetooth-accessible DUML command interface of multiple DJI drone models. The interface accepts unauthenticated commands from an attacker within Bluetooth range, permitting modification of wireless configuration, including the SSID, pre-shared key, MAC address, regulatory country code, and radio channel. An attacker can replace the Wi-Fi pre-shared key with a known value to join the drone's internal wireless network. Crafted commands can also disable or restart Wi-Fi or Bluetooth, disconnect wireless clients, and reset wireless configuration. Affected firmware includes DJI Neo through 01.00.0400, Neo 2 through 01.00.0500, Flip through 01.00.1200, Air 3 through 01.00.1600, Air 3S through 01.00.1400, Avata 2 through 01.00.0400, Avata 360 through 01.00.0300, Mavic 3 through 01.00.1400, Mavic 3 Classic through 01.00.0800, Mavic 3 Pro through 01.01.0700, Mavic 4 Pro through 01.00.0500, Mini 2 through 01.07.0200, Mini 3 through 01.00.0500, Mini 3 Pro through 01.00.0900, Mini 4 Pro through 01.00.1100, and Mini 5 Pro through 01.00.0600.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This is a functional Python BLE proof of concept for CVE-2026-78306, not merely a detector. Its primary entry point, ble_console.py, loads a JSON command registry, scans for a nearby BLE device using bleak, opens a GATT connection, sends DUML frames, and displays/decodes asynchronous replies. The intended vulnerability is inconsistent trusted-UUID enforcement: the repository labels only retrieval of SSID, PSK, and AP MAC as authenticated, while exposing many other commands to an attacker in Bluetooth range. Repository structure: ble_transport.py implements scanning, GATT characteristic selection, notification subscription, request/reply correlation, BLE destination filtering, and optional trusted-UUID registration. duml_protocol.py builds and parses DUML v1 packets with DJI CRC8/CRC16 checksums and includes packet helpers. commands.json is the operational command catalogue, including read, write-configuration, reset/system, parameter, macro, and custom-frame actions. payload_builders.py safely-ish serializes interactive configuration values, duml_decoders.py interprets response codes and known response formats, and parameters.py hashes, reads, writes, and resets named DJI configuration parameters. flyc_parameters.txt supplies a large parameter-name wordlist; terminal.py provides the interactive terminal UI. Notable impact-oriented capabilities include retrieving nonprotected device/radio details; changing Wi-Fi SSID, PSK, MAC, country, channel, and band; toggling radio-related settings; restarting Wi-Fi; issuing system/reset commands; changing or resetting configuration parameters; and emitting arbitrary custom DUML frames. The code warns that some reset commands can erase configuration, stored media, or forensic logs. Commands addressed to handlers listed in the Bluetooth blacklist are locally blocked by the tool, and the tool explicitly notes that no Bluetooth reply does not prove a command failed.
This is a standalone Python proof-of-concept repository for CVE-2026-78306, an alleged authorization flaw in DJI aircraft Bluetooth DUML handling. Its main entry point, `ble_console.py`, loads a data-driven command catalogue from `commands.json`, scans for a nearby BLE device using Bleak, connects to its GATT services, and offers an interactive command menu. It can optionally submit a trusted UUID registration request, although the core issue is that commands other than SSID, PSK, and MAC retrieval are represented as not requiring the same authorization state. `ble_transport.py` implements BLE discovery, GATT write/notification handling, reply correlation by DUML sequence number, destination blacklist awareness, and trusted-UUID registration. `duml_protocol.py` builds/parses DUML v1 packets and implements CRC-8/CRC-16 checks; it also contains frame helpers, including flight-control-related frame constructors and raw IPv4/UDP packet construction helpers, though the described main console attack path is BLE GATT. `commands.json` is the operational command registry and labels actions by read/write/danger tiers. It includes read/reconnaissance requests, Wi-Fi configuration changes, radio control, parameter actions, macros such as PSK change followed by Wi-Fi restart, read-command probing, and an arbitrary custom-frame option. `payload_builders.py` interactively formats Wi-Fi SSID, PSK, country-code, MAC, channel, BSS type, radio-power, and raw payload fields. `parameters.py` hashes named configuration parameters and supports reading metadata, writing encoded values, and resetting parameters against `dji_config_store` or flight-controller destinations; `flyc_parameters.txt` supplies a large parameter-name corpus. `duml_decoders.py` translates return values and command responses into user-readable facts, while `terminal.py` provides the console UI. There are no hard-coded external command-and-control hosts, IP addresses, or HTTP requests in the supplied exploit logic; its operative target is a locally discoverable DJI BLE GATT service.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.