CVE-2026-77812 | DJI Neo 2 DUML Protocol missing encryption
A vulnerability was found in DJI Air 3, Air 3S, Avata 2, Avata 360, Flip, Mavic 3, Mavic 3 Classic, Mavic 3 Pro, Mavic 4 Pro, Mini 2, Mini 3, Mini 3 Pro, Mini 4 Pro, Mini 5 Pro, Neo and Neo 2. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component DUML Protocol. Performing a manipulation results in missing encryption of sensitive data.
This vulnerability is cataloged as CVE-2026-77812. The attack must be initiated from a local position. There is no exploit available.VulDB Recent EntriesRead More