CVE-2026-26673 Details
Description
An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI Enhanced-WiFi transmission subsystem
A denial-of-service vulnerability has been identified in several DJI drone models, including the Mavic Mini, Spark, Mavic Air, Mini, and Mini SE versions 0.1.00.0500 and below. The issue arises in the DJI Enhanced-WiFi transmission subsystem, which uses WEP encryption, allowing remote attackers to inject crafted IEEE 802.11 frames into the communication channel between the drone and its remote controller. This injection can replay a static pairing byte sequence that, when decrypted and re-encrypted, forces a disconnection, disrupting control and telemetry.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ByteMe1001/DJI-CatNect | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| dji mavic mini firmware | <= 01.00.0600 |
CPE
Remediation
| |
| dji mavic mini | All versions |
CPE
Remediation
| |
| dji spark firmware | <= 01.00.1000 |
CPE
Remediation
| |
| dji spark | All versions |
CPE
Remediation
| |
| dji mini se firmware | <= 01.02.0000 |
CPE
Remediation
| |
| dji mini se | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 5, 2026 | Initial Analysis | [email protected] |
| Mar 4, 2026 | CVE Modified | CISA-ADP |
| Mar 4, 2026 | New CVE Received | [email protected] |