Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects DJI drones, allowing unauthorized users to upload files that can fill up drone storage, potentially disrupting flight recording and future updates. The issue stems from an FTP service with weak credentials and no file size limits.
- Drones can be overloaded with files.
- Flight data recording and updates may fail.
- Confirm if your drone operations are at risk.
Attack Path
How an attacker could exploit the issue
An attacker who can access the drone's internal network or connect via its USB interface can leverage an FTP service that accepts hardcoded credentials. This allows them to upload files without restriction into a specific upgrade directory. By overwhelming the drone's storage with these uploads, the attacker can prevent critical flight data from being recorded and potentially halt firmware updates. The uploaded files are persistent even after a reboot or factory reset.
- Requires internal network or USB access.
- Triggered by uploading files via FTP.
- Prevents flight records and updates.
Live Threat
Current exploitation, exposure, and threat context
An attacker with internal network access or a USB connection to the drone could exploit this vulnerability. This could lead to the drone's storage being completely filled, preventing it from recording crucial flight data, logs, and telemetry. In some scenarios, this might also interfere with the drone's ability to perform firmware updates.
- Flight records and logs at risk.
- Storage exhaustion via file uploads.
- Prevents flight data recording.
Operational Fix
Recommended remediation, mitigation, and detection steps
Real-world action for this vulnerability likely involves DJI drone owners and potentially IT or operations teams managing drone fleets. The immediate practical move is to identify all affected DJI drone models within your organization, confirm their network accessibility (especially if used in environments with internal network access or via USB RNDIS), and determine their criticality to ongoing operations before planning firmware updates.
- Drone fleet owners should lead remediation.
- Verify drone network exposure and flight records.
- Plan and coordinate vendor firmware updates.