Описание
A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious firmware upgrade packet.
Ссылки
- ExploitThird Party Advisory
- Technical DescriptionThird Party Advisory
- Third Party Advisory
- Product
- ExploitThird Party Advisory
- Technical DescriptionThird Party Advisory
- Third Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 01.00.0510 (исключая)
Одновременно
cpe:2.3:o:dji:mavic_2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dji:mavic_2:-:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00464
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-78
Связанные уязвимости
github
больше 3 лет назад
A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious firmware upgrade packet.
EPSS
Процентиль: 64%
0.00464
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-78