CVE-2026-78251 | DJI Neo 2 FTP Service /blackbox/upgrade/ hard-coded credentials

SecurityVulns

A vulnerability marked as problematic has been reported in DJI Air 3, Air 3S, Avata 2, Avata 360, Flip, Mavic 3, Mavic 3 Classic, Mavic 3 Pro, Mavic 4 Pro, Mini 2, Mini 3, Mini 3 Pro, Mini 4 Pro, Mini 5 Pro, Neo and Neo 2. This impacts an unknown function of the file /blackbox/upgrade/ of the component FTP Service. The manipulation leads to hard-coded credentials.

This vulnerability is documented as CVE-2026-78251. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More