DJI's vulnerability footprint centers on consumer and commercial unmanned-aircraft systems, with recurring disclosures affecting drone firmware and control products such as the Mini SE and Spark, alongside the underlying firmware components. The observed weakness classes cluster around cleartext transmission of sensitive data, OS command injection, and authentication mechanisms that rely on IP-address validation, reflecting the communications and access-control demands of networked autonomous systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dji over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1074HIGH Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long (1) DataPath or (2) DownloadPath attribu | Feb 22, 2007 | 9.3 | 36 | NO | YES |
CVE-2026-26673HIGH An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI Enhanced-WiFi transmission subsy | Mar 4, 2026 | 7.5 | 26 | NO | NO |
CVE-2022-46415MEDIUM DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool. To accomplish this, the attacker would first need to | Mar 27, 2023 | 5.9 | 20 | NO | NO |
CVE-2020-29664HIGH A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious firmware upgrade packet. | Feb 18, 2021 | 7.8 | 20 | NO | NO |
CVE-2022-29945HIGH DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol. | Apr 29, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dji.
Media articles that mention a CVE ID that affects a product developed by Dji — matched by CVE ID, not by vendor name.