DJI records
9 published records for vendor dji.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read1
- CWE-129 Improper Validation of Array Index1
- CWE-291 Reliance on IP Address for Authentication1
- CWE-306 Missing Authentication for Critical Function1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-400 Uncontrolled Resource Consumption1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2007-1074Proof of concept | Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long dji · newsbin pro | Critical9.3 | — | 7.5% | Feb 22, 2007 |
31Monitor | CVE-2020-29664No exploit | A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a maldji · mavic 2 firmware · CWE-78 | High7.8 | — | 1.5% | Feb 18, 2021 |
30Monitor | CVE-2022-29945No exploit | DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScopedji · mavic 3 firmware · CWE-319 | High7.5 | — | 0.7% | Apr 29, 2022 |
30Monitor | CVE-2026-26673No exploit | An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via dji · mavic mini firmware · CWE-400 | High7.5 | — | 0.6% | Mar 4, 2026 |
27Monitor | CVE-2023-51454No exploit | A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to dji · mavic 3 pro · CWE-787 | Medium6.8 | — | 0.2% | Apr 2, 2024 |
27Monitor | CVE-2023-51455No exploit | A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow dji · mavic 3 pro · CWE-129 | Medium6.8 | — | 0.2% | Apr 2, 2024 |
27Monitor | CVE-2023-51456No exploit | A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attackdji · mavic 3 pro · CWE-125 | Medium6.8 | — | 0.2% | Apr 2, 2024 |
23Monitor | CVE-2022-46415No exploit | DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool.dji · spark firmware · CWE-291 | Medium5.9 | — | 0.9% | Mar 27, 2023 |
20Monitor | CVE-2023-6949No exploit | A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 dji · mini 3 pro · CWE-306 | Medium5.2 | — | 0.2% | Apr 2, 2024 |
- CVE-2007-107439Monitor
Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long
CriticalCVSS 9.3Proof of conceptEPSS 7%dji · newsbin proFeb 22, 2007
- CVE-2020-2966431Monitor
A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a mal
HighCVSS 7.8No exploitEPSS 1%dji · mavic 2 firmwareFeb 18, 2021
- CVE-2022-2994530Monitor
DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope
HighCVSS 7.5No exploitEPSS 1%dji · mavic 3 firmwareApr 29, 2022
- CVE-2026-2667330Monitor
An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via
HighCVSS 7.5No exploitEPSS 1%dji · mavic mini firmwareMar 4, 2026
- CVE-2023-5145427Monitor
A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to
MediumCVSS 6.8No exploitEPSS 0%dji · mavic 3 proApr 2, 2024
- CVE-2023-5145527Monitor
A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow
MediumCVSS 6.8No exploitEPSS 0%dji · mavic 3 proApr 2, 2024
- CVE-2023-5145627Monitor
A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attack
MediumCVSS 6.8No exploitEPSS 0%dji · mavic 3 proApr 2, 2024
- CVE-2022-4641523Monitor
DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool.
MediumCVSS 5.9No exploitEPSS 1%dji · spark firmwareMar 27, 2023
- CVE-2023-694920Monitor
A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80
MediumCVSS 5.2No exploitEPSS 0%dji · mini 3 proApr 2, 2024