Mavic 3 Classic
12 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Mavic 3 Classic, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
Mavic 3 Classic CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 5 |
| 2026-09 | 0 |
Severity
How the 12 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Medium4
- Low3
Latest CVEs
The 12 most recently published vulnerabilities affecting Mavic 3 Classic.
- CVE-2026-78321DJI Drone HTTP Media Server Denial of Service via Connection Pool Exhaustion—
- CVE-2026-78306DJI Drone Bluetooth Interface Unauthenticated DUML Command Execution—
- CVE-2026-78255DJI Drone HTTP Media Server Allows Unauthenticated Access to Stored Media—
- CVE-2026-78251DJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox Directory—
- CVE-2026-77812Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE—
- CVE-2023-51456A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to trigger an out-of-bound read/write into the process...6.8
- CVE-2023-51455A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to corrupt a controlled memory location due t...6.8
- CVE-2023-51454A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to overwrite a pointer in the process memory through a craft...6.8
- CVE-2023-51453A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payl...3.0
- CVE-2023-51452A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service through a crafted payl...3.0
- CVE-2023-6951A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the WPA2 PSK key and authenticate without permission to ...6.6
- CVE-2023-6948A Buffer Copy without Checking Size of Input issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to cause a crash of the service throu...3.0
Product grouping is registry-driven, with AI assist and human review. How it works