DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://www.theverge.com/2022/4/28/23046916/dji-aeroscope-signals-not-encrypted-drone-tracking | third party advisory press/media coverage |
https://twitter.com/d0tslash/status/1519774807776284672 | third party advisory |
https://twitter.com/StarFire2258/status/1519767091829637120 | third party advisory |