External risk intelligence

DJI Drone FTP Storage Exhaustion Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-78251

The vulnerability exists within the internal network or USB interface of a drone, which is not designed to be exposed to the public internet. Access typically requires physical proximity or direct connection to the device's local communication channel, making public internet reachability for this specific service effectively non-existent in standard operation.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects DJI drones, allowing unauthorized users to upload files that can fill up drone storage, potentially disrupting flight recording and future updates. The issue stems from an FTP service with weak credentials and no file size limits.

  • Drones can be overloaded with files.
  • Flight data recording and updates may fail.
  • Confirm if your drone operations are at risk.

Attack Path

How an attacker could exploit the issue

An attacker who can access the drone's internal network or connect via its USB interface can leverage an FTP service that accepts hardcoded credentials. This allows them to upload files without restriction into a specific upgrade directory. By overwhelming the drone's storage with these uploads, the attacker can prevent critical flight data from being recorded and potentially halt firmware updates. The uploaded files are persistent even after a reboot or factory reset.

  • Requires internal network or USB access.
  • Triggered by uploading files via FTP.
  • Prevents flight records and updates.

Live Threat

Current exploitation, exposure, and threat context

An attacker with internal network access or a USB connection to the drone could exploit this vulnerability. This could lead to the drone's storage being completely filled, preventing it from recording crucial flight data, logs, and telemetry. In some scenarios, this might also interfere with the drone's ability to perform firmware updates.

  • Flight records and logs at risk.
  • Storage exhaustion via file uploads.
  • Prevents flight data recording.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world action for this vulnerability likely involves DJI drone owners and potentially IT or operations teams managing drone fleets. The immediate practical move is to identify all affected DJI drone models within your organization, confirm their network accessibility (especially if used in environments with internal network access or via USB RNDIS), and determine their criticality to ongoing operations before planning firmware updates.

  • Drone fleet owners should lead remediation.
  • Verify drone network exposure and flight records.
  • Plan and coordinate vendor firmware updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the software affected by CVE-2026-78251?

This vulnerability affects various DJI drone models, including the Neo, Mavic, Air, Avata, and Mini series. These devices utilize an onboard FTP service designed for system maintenance and updates. While these drones serve as sophisticated aerial platforms for photography and data collection, this specific service manages internal files, logs, and telemetry that ensure the aircraft functions correctly during and between flights.

How does CVE-2026-78251 relate to hardcoded credentials?

This issue is classified under CWE-798: Use of Hardcoded Credentials. The drone's FTP service relies on default passwords shared across multiple models, allowing unauthorized access. Once authenticated, an attacker can bypass size and quantity restrictions to flood the device's storage. This effectively turns an administrative service into a point of failure, as the drone cannot discern legitimate system files from malicious data uploads.

Does remote internet access trigger this vulnerability?

No, standard internet access does not trigger this. The bug requires direct interaction with the drone's internal network or a physical connection via the USB RNDIS interface. Simply flying the drone or connecting it to a standard home Wi-Fi network does not necessarily provide the specific pathway an attacker needs to perform these unauthorized file uploads.

How should I assess the relevance of this CVE to my devices?

Per Halo Surface Signal, this vulnerability is very unlikely to be exploited via the public internet because the FTP service is meant for local communication. You should evaluate if your drone is physically accessible or connected to an internal network where untrusted parties could reach the device's management interface. If the drone remains isolated or is used only in secure, offline environments, the risk profile changes significantly.

What is the first step to remediate this vulnerability?

The primary response is to apply the firmware update provided by the vendor. Before updating, inventory your fleet to identify affected models and assess whether their specific operational environment exposes them to local network or USB access. Prioritize updating devices that are regularly connected to shared or internal networks, and ensure your team is prepared to verify storage integrity after applying the patches.

References