CVE-2023-6950: Dji Mini 3 Pro

Low severity, CVSS 3.0. EPSS: 0.2% chance of exploitation in the next 30 days.

An Improper Input Validation vulnerability affecting the FTP service running on the DJI Mavic Mini 3 Pro could allow an attacker to craft a malicious packet containing a malformed path provided to the FTP SIZE command that leads to a denial-of-service attack of the FTP service itself.

Affected products

  • Dji Mini 3 Pro: before 01.00.1200 (fixed in 01.00.1200)

Published 2024-04-02. Last modified 2026-06-17.