CVE-2022-46415 affects DJI Spark drones running firmware version 01.00.0900. It allows a remote attacker to exhaust the device's DHCP IP address pool, preventing legitimate connections. This medium-severity vulnerability requires the attacker to first gain access to the drone's internal Wi-Fi network (e.g., by guessing the password) and then send numerous DHCP requests, leading to a denial of service. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
01.00.0900CPE matchmatch criteria | cpe:2.3:o:dji:spark_firmware:01.00.0900:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.