CVE-2023-6951 describes a Use of Weak Credentials vulnerability in the Wi-Fi network of several DJI drone models, including Mavic 3 Pro, Mavic 3, and Mini 3 Pro, allowing remote attackers to derive the WPA2 PSK key and gain unauthorized access. This medium-severity vulnerability (CVSS 6.6) requires an attacker to be within Wi-Fi range and could lead to unauthorized interaction with drone services and potential decryption of Wi-Fi traffic during QuickTransfer mode. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| DJI | Matrice 300 | >= 0, < 57.00.01.00CNA affecteddefault unaffected | |
| DJI | Matrice M30 | >= 0, < 07.01.0022CNA affecteddefault unaffected | |
| DJI | Mavic 3 Classic | >= 0, < 01.00.0500CNA affecteddefault unaffected | |
| DJI | Mavic 3 Enterprise | >= 0, < 7.01.10.03CNA affecteddefault unaffected | |
| DJI | Mavic 3 Pro | >= 0, < 01.01.0300CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.