Causal model
What has to happen for this consequence to hold?
2 candidate paths · explicit source, inference, and assumption boundaries.
Privacy · Dominant path
Perception privacy
Decrypted live video, navigation, and telemetry reveal the drone’s current surroundings and operational world state.
One cross-boundary bridge
QuickTransfer key derivation crosses from the companion app into the drone Wi-Fi network and decrypted operator-device traffic, without demonstrating control authority.
EvidenceNo direct citation — inspect the declared inference or assumption.
Safety-driving perception or intimate data
Decrypted live video, navigation, and telemetry reveal the drone’s current surroundings and operational world state.
EvidenceNo direct citation — inspect the declared inference or assumption.
Perception privacy
Decrypted live video, navigation, and telemetry reveal the drone’s current surroundings and operational world state.
EvidenceNo direct citation — inspect the declared inference or assumption.
Patch, reset, or reconfiguration
Firmware update fixes it, no recall and key rotation across fleet.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
Adjacent Wi-Fi RF proximity plus operator using QuickTransfer.
- Execution complexity
EC 4 - Straightforward operation
Single-step PSK derivation from predictable inputs once known.
- Exposure
EX 2 - Access position limits exposure
The technique is easier to perform than it is to position against a target, so access is the constraining factor.
Consequence
- Physical / safety
PH 0 - No direct physical effect
Access to the drone’s camera and telemetry exposes people and places without directly changing the aircraft’s physical behavior.
- Data / perception
DP 4 - Safety-driving perception or intimate data
Decrypted live video, navigation, and telemetry reveal the drone’s current surroundings and operational world state.
- Authority
AT 2 - Bounded function authority
Bounded unauthorized access to drone network services, no control-plane and administrator authority, no integrity or availability impact.
Scale and recovery
- Chainability
CH 2 - One cross-boundary bridge
QuickTransfer key derivation crosses from the companion app into the drone Wi-Fi network and decrypted operator-device traffic, without demonstrating control authority.
- Reuse scale
SR 4 - Shared fleet-wide primitive
Weak key derivation is systematic across the affected model and firmware list (shared derivation scheme is portable technique).
- Execution scale
SX 2 - Proximity-bound repetition
The attacker must be within Wi-Fi range of each drone during QuickTransfer, so collection cannot be launched remotely across the fleet.
- Recovery burden
OR 2 - Patch, reset, or reconfiguration
Firmware update fixes it, no recall and key rotation across fleet.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Decrypted live video, navigation, and telemetry reveal the drone’s current surroundings and operational world state.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:4/EX:2/PH:0/DP:4/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →Privacy · Supporting path
Data privacy
Transferred recordings and exposed service state reveal sensitive personal and proprietary data beyond the live perception stream.
One cross-boundary bridge
The derived key crosses the app, drone-network, and radio boundaries to expose traffic and services, but the record does not demonstrate a pivot into flight control.
EvidenceNo direct citation — inspect the declared inference or assumption.
Sensitive device or personal data
Transferred recordings and exposed service state reveal sensitive personal and proprietary data beyond the live perception stream.
EvidenceNo direct citation — inspect the declared inference or assumption.
Data privacy
Transferred recordings and exposed service state reveal sensitive personal and proprietary data beyond the live perception stream.
EvidenceNo direct citation — inspect the declared inference or assumption.
Patch, reset, or reconfiguration
Vendor firmware update remedies.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
Wi-Fi range and operator QuickTransfer in use.
- Execution complexity
EC 4 - Straightforward operation
The attacker derives the predictable QuickTransfer key, joins the drone network, and then reads reachable traffic or services.
- Exposure
EX 2 - Access position limits exposure
The technique is easier to perform than it is to position against a target, so access is the constraining factor.
Consequence
- Physical / safety
PH 0 - No direct physical effect
The captured imagery and telemetry create a privacy consequence without independently driving physical actuation.
- Data / perception
DP 3 - Sensitive device or personal data
Transferred recordings and exposed service state reveal sensitive personal and proprietary data beyond the live perception stream.
- Authority
AT 2 - Bounded function authority
Bounded network access to drone services, confidentiality-only, no administrator and firmware and command authority.
Scale and recovery
- Chainability
CH 2 - One cross-boundary bridge
The derived key crosses the app, drone-network, and radio boundaries to expose traffic and services, but the record does not demonstrate a pivot into flight control.
- Reuse scale
SR 4 - Shared fleet-wide primitive
Derivation weakness reusable across affected firmware and models.
- Execution scale
SX 2 - Proximity-bound repetition
Proximity-bound per target, not remote fleet mass-exploit.
- Recovery burden
OR 2 - Patch, reset, or reconfiguration
Vendor firmware update remedies.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandHIGH
- No adjustment
The HIGH base band remains final because no separate cap or systemic uplift applies. Transferred recordings and exposed service state reveal sensitive personal and proprietary data beyond the live perception stream.
- Final candidate bandHIGH
Technical vector
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:4/EX:2/PH:0/DP:3/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →Triage implication
Verify the privacy transition before acting on the band.
Protect the outward data or sensor boundary and verify what sensitive behavior can be reconstructed, not only what raw fields are exposed.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:NCVE recordsCVE-2023-6951
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses DJI Mavic 3 Wi-Fi Weak Credentials / QuickTransfer Key Derivation (CVE-2023-6951) at CRITICAL — the worst of 2 risk paths (perception). The dominant consequence is exposure of sensor or biometric data.
Vulnerability
DJI Mavic 3 Wi-Fi Weak Credentials / QuickTransfer Key Derivation (CVE-2023-6951). Reported attack vector: Adjacent network (drone Wi-Fi range).
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
PERCEPTION_PRIVACY → CRITICAL
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:4/EX:2/PH:0/DP:4/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLE
Exposure EX=2 (reachability-bound) · bands PH=MONITOR · DP=CRITICAL · AT=ELEVATED → base CRITICAL · caps privacy-only cap → assessed CRITICAL.
- RE2 — adjacent Wi-Fi RF proximity (AV:A) plus operator using QuickTransfer (UI:R).
- EC4 — AC:L single-step PSK derivation from predictable inputs once known.
- DP4 — decrypted live drone telemetry/media = camera/nav/spatial perception state of an autonomous vehicle.
- perception_feeds_action — false: attacker only observes (C:H, I:N, A:N); no demonstrated injection back into flight/nav decisions.
- AT2 — bounded unauthorized access to drone network services, no control-plane/admin authority, no I/A impact.
- PH0 — no actuation/safety effect demonstrated.
- CH2 — + boundary_crossing: crosses app/device/RF boundary (joins device net, decrypts operator-device traffic) but no demonstrated cross-domain authority transfer.
- SR4 — weak key derivation is systematic across the affected model/firmware list (shared derivation scheme = portable technique).
- SX2 — per-device proximity-bound, must be in RF range of each target, not fleet-remote.
- OR2 — firmware update fixes it, no recall/key rotation across fleet.
- EV2 — report-backed (Nozomi writeup), LS PATCH_AVAILABLE. Not known exploited in wild.
DATA_PRIVACY → HIGH
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:4/EX:2/PH:0/DP:3/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLE
Exposure EX=2 (reachability-bound) · bands PH=MONITOR · DP=HIGH · AT=ELEVATED → base HIGH · caps privacy-only cap → assessed HIGH.
- Distinct terminal consequence: confidentiality of transferred media/files and exposure of drone network services (foothold), separate from live perception interception.
- RE2 — Wi-Fi range + operator QuickTransfer in use (AV:A, UI:R).
- EC4 — AC:L derive-PSK-and-join.
- DP3 — transferred media/recorded content and exposed service/op-state = sensitive proprietary/PII-class data rather than live world-model feed.
- AT2 — bounded network access to drone services, confidentiality-only, no admin/firmware/command authority (I:N, A:N).
- PH0 — no safety/physical effect.
- CH2 — + boundary_crossing: app-to-device-network-to-RF boundary crossing, foothold on services, but no demonstrated authority pivot to control.
- SR4 — derivation weakness reusable across affected firmware/models.
- SX2 — proximity-bound per target, not remote fleet mass-exploit.
- OR2 — vendor firmware update remedies.
- EV2 — report-backed, LS PATCH_AVAILABLE, no in-the-wild exploitation.
Published baseline
- v3.1 6.6 MEDIUM —
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N— Nozomi Networks via NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0020 (“DJI Mavic 3 Wi-Fi Weak Credentials / QuickTransfer Key Derivation (CVE-2023-6951)”), paths.cfse.ai/CPATH-2026-0020 (published 2026-06-03).