Security Impact

From vulnerability discovery to responsible disclosure

Registered vulnerabilities documenting concrete security issues, their technical impact, and the collaborative work behind their disclosure.

12Registered CVEs
5Critical severity
9.8Highest CVSS
Practical security impact

Security findings backed by public records

Each disclosure below links to an external vulnerability record and summarizes the affected component, attack vector, and assessed severity.

Disclosed withAbdelrahman Yousef, Lucas Visintin
Industry recognition

Responsible disclosure recognized in practice

External recognition for responsibly reported security concerns beyond registered CVEs.

Jul, 2026 DJI Security Response Center

Listed among DJI Security Contributors

πŸ›‘οΈ My student Abdelrahman Yousef and I are listed among DJI Security Contributors for December 2025–June 2026 in the Devices and APPs category, recognizing our responsible disclosure work to help make DJI platforms safer.

View recognition
Disclosure portfolio

Registered vulnerabilities

Severity is based on the CVSS score stored with each record.

Aug 24, 2026Medium
6.0CVSS

CVE-2026-78321

The HTTP media server on DJI drones does not sufficiently limit incoming connections or request rates. An attacker on the internal network can exhaust the connection pool and prevent the DJI Fly application from retrieving media in QuickTransfer mode.

Aug 24, 2026High
8.5CVSS

CVE-2026-78306

DJI drones expose an unauthenticated DUML command interface over Bluetooth. A nearby attacker can modify wireless settings, obtain access to the internal Wi-Fi network, disrupt Wi-Fi and Bluetooth connections, and potentially reach the flight-control interface.

Aug 24, 2026High
8.7CVSS

CVE-2026-78255

The HTTP media server on DJI drones serves stored photos and videos without authenticating clients. An attacker on the drone's internal network can enumerate predictable filenames and exfiltrate media that may reveal sensitive locations, people, and operator routines.

Aug 24, 2026Critical
9.3CVSS

CVE-2026-78251

DJI drones expose an FTP service with shared hardcoded credentials and no storage quotas in /blackbox/upgrade/. An attacker with internal-network or USB RNDIS access can exhaust storage, overwrite files, prevent flight records and telemetry from being written, and interfere with firmware updates.

Aug 21, 2026Critical
9.4CVSS

CVE-2026-77812

DJI drones transmit DUML messages over Bluetooth Low Energy without encryption, exposing Wi-Fi credentials and a trusted-client identifier to a nearby passive attacker. The recovered credentials can be used to join the drone's internal network and interact with exposed services.

2023Critical
9.8CVSS

CVE-2023-48050

SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the controllers/controllers.py component.

2023Critical
9.8CVSS

CVE-2023-48049

A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through 13.0.1.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the name parameter in controllers/main.py component.

2023High
8.8CVSS

CVE-2023-40958

A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the query parameter in models/base_client.py component.

2023High
8.8CVSS

CVE-2023-40957

A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the request parameter in models/base_client.py component.

2023High
8.8CVSS

CVE-2023-40956

A SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute arbitrary code via the name parameter in controllers/main.py component.

2023High
8.8CVSS

CVE-2023-40955

A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a rem

2023Critical
9.8CVSS

CVE-2023-40954

A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component.