Prnewswire DJI Drone Security Assessment Finds No Major Vulnerabilities Amid Ban Debate
Article Content
- •OnDefend's assessment found no critical or high-risk vulnerabilities in DJI drones.
- •Ten low-risk findings were identified, primarily related to application security configurations.
- •DJI is appealing its FCC Covered List designation, citing lack of evidence for security concerns.
DJI has released findings from an independent security assessment conducted by OnDefend, which reported zero critical, high, or medium-risk vulnerabilities in its Air 3S and Matrice 4E drone systems. The assessment, spanning five months, included rigorous testing of hardware, firmware, and software, with no evidence of data transmission outside the U.S. or hidden backdoors. The report identified ten low-risk findings related to application security configurations, but none posed a significant threat to drone operations. DJI is appealing its designation on the FCC Covered List, arguing that the concerns are unfounded and calling for evidence-based policy decisions. The findings are expected to impact thousands of users and businesses reliant on DJI drones for various applications. The assessment was conducted independently, with consumer units purchased without prior notice to DJI.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…