CVE-2026-26673

A

n issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI Enhanced-WiFi transmission subsystem

References
Link Resource
https://github.com/ByteMe1001/DJI-CatNect Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dji:mavic_mini_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dji:mavic_mini:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dji:spark_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dji:spark:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dji:mini_se_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dji:mini_se:-:*:*:*:*:*:*:*

History

05 Mar 2026, 18:05

Type Values Removed Values Added
CPE cpe:2.3:o:dji:mavic_mini_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dji:mini_se:-:*:*:*:*:*:*:*
cpe:2.3:h:dji:mavic_mini:-:*:*:*:*:*:*:*
cpe:2.3:o:dji:mini_se_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dji:spark_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dji:spark:-:*:*:*:*:*:*:*
References () https://github.com/ByteMe1001/DJI-CatNect - () https://github.com/ByteMe1001/DJI-CatNect - Exploit, Third Party Advisory
First Time Dji
Dji mavic Mini Firmware
Dji mini Se Firmware
Dji spark Firmware
Dji spark
Dji mavic Mini
Dji mini Se

04 Mar 2026, 18:16

Type Values Removed Values Added
CWE CWE-400
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

04 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-04 16:16

Updated : 2026-03-05 18:05


NVD link : CVE-2026-26673

Mitre link : CVE-2026-26673

CVE.ORG link : CVE-2026-26673


JSON object : View

CWE
CWE-400

Uncontrolled Resource Consumption