Vulnerabilities > DJI

DATE CVE VULNERABILITY TITLE RISK
2023-03-27 CVE-2022-46415 Unspecified vulnerability in DJI Spark Firmware 01.00.0900
DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool.
network
high complexity
dji
5.9
2022-04-29 CVE-2022-29945 Cleartext Transmission of Sensitive Information vulnerability in DJI products
DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.
network
low complexity
dji CWE-319
7.5
2021-02-18 CVE-2020-29664 OS Command Injection vulnerability in DJI Mavic 2 Firmware
A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious firmware upgrade packet.
local
low complexity
dji CWE-78
7.8