CVE-2026-26673

An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI Enhanced-WiFi transmission subsystem
References
Link Resource
https://github.com/ByteMe1001/DJI-CatNect Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dji:mavic_mini_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dji:mavic_mini:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dji:spark_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dji:spark:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dji:mini_se_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dji:mini_se:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-04 16:16

Updated : 2026-03-05 18:05


NVD link : CVE-2026-26673

Mitre link : CVE-2026-26673

CVE.ORG link : CVE-2026-26673


JSON object : View

Products Affected

dji

  • spark_firmware
  • mavic_mini_firmware
  • mini_se_firmware
  • mini_se
  • spark
  • mavic_mini
CWE
CWE-400

Uncontrolled Resource Consumption