CPATH-2026-0020 · Drone / autonomous systems

DJI Mavic 3 Wi-Fi Weak Credentials / QuickTransfer Key Derivation (CVE-2023-6951)

A dominant perception privacy path connects the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Dominant pathPerception privacy

This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Privacy · Dominant path

Perception privacy

Decrypted live video, navigation, and telemetry reveal the drone’s current surroundings and operational world state.

CRITICAL
  1. accessSource-backed

    Proximity or local access

    Adjacent Wi-Fi RF proximity plus operator using QuickTransfer.

    EvidenceNVD

  2. boundaryModel inference

    One cross-boundary bridge

    QuickTransfer key derivation crosses from the companion app into the drone Wi-Fi network and decrypted operator-device traffic, without demonstrating control authority.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Safety-driving perception or intimate data

    Decrypted live video, navigation, and telemetry reveal the drone’s current surroundings and operational world state.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Perception privacy

    Decrypted live video, navigation, and telemetry reveal the drone’s current surroundings and operational world state.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Firmware update fixes it, no recall and key rotation across fleet.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

Adjacent Wi-Fi RF proximity plus operator using QuickTransfer.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Single-step PSK derivation from predictable inputs once known.

Source-backedNVD
ExposureEX 2
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 0
No direct physical effect

Access to the drone’s camera and telemetry exposes people and places without directly changing the aircraft’s physical behavior.

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

Decrypted live video, navigation, and telemetry reveal the drone’s current surroundings and operational world state.

Model inference
AuthorityAT 2
Bounded function authority

Bounded unauthorized access to drone network services, no control-plane and administrator authority, no integrity or availability impact.

Model inference
Scale and recovery
ChainabilityCH 2
One cross-boundary bridge

QuickTransfer key derivation crosses from the companion app into the drone Wi-Fi network and decrypted operator-device traffic, without demonstrating control authority.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

Weak key derivation is systematic across the affected model and firmware list (shared derivation scheme is portable technique).

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

The attacker must be within Wi-Fi range of each drone during QuickTransfer, so collection cannot be launched remotely across the fleet.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Firmware update fixes it, no recall and key rotation across fleet.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Decrypted live video, navigation, and telemetry reveal the drone’s current surroundings and operational world state.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:4/EX:2/PH:0/DP:4/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Privacy · Supporting path

Data privacy

Transferred recordings and exposed service state reveal sensitive personal and proprietary data beyond the live perception stream.

HIGH
  1. accessSource-backed

    Proximity or local access

    Wi-Fi range and operator QuickTransfer in use.

    EvidenceNVD

  2. boundaryModel inference

    One cross-boundary bridge

    The derived key crosses the app, drone-network, and radio boundaries to expose traffic and services, but the record does not demonstrate a pivot into flight control.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Sensitive device or personal data

    Transferred recordings and exposed service state reveal sensitive personal and proprietary data beyond the live perception stream.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Data privacy

    Transferred recordings and exposed service state reveal sensitive personal and proprietary data beyond the live perception stream.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Vendor firmware update remedies.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

Wi-Fi range and operator QuickTransfer in use.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

The attacker derives the predictable QuickTransfer key, joins the drone network, and then reads reachable traffic or services.

Source-backedNVD
ExposureEX 2
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 0
No direct physical effect

The captured imagery and telemetry create a privacy consequence without independently driving physical actuation.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Transferred recordings and exposed service state reveal sensitive personal and proprietary data beyond the live perception stream.

Model inference
AuthorityAT 2
Bounded function authority

Bounded network access to drone services, confidentiality-only, no administrator and firmware and command authority.

Model inference
Scale and recovery
ChainabilityCH 2
One cross-boundary bridge

The derived key crosses the app, drone-network, and radio boundaries to expose traffic and services, but the record does not demonstrate a pivot into flight control.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

Derivation weakness reusable across affected firmware and models.

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

Proximity-bound per target, not remote fleet mass-exploit.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Vendor firmware update remedies.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandHIGH
  2. No adjustment

    The HIGH base band remains final because no separate cap or systemic uplift applies. Transferred recordings and exposed service state reveal sensitive personal and proprietary data beyond the live perception stream.

  3. Final candidate bandHIGH
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:4/EX:2/PH:0/DP:3/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the privacy transition before acting on the band.

Protect the outward data or sensor boundary and verify what sensitive behavior can be reconstructed, not only what raw fields are exposed.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 6.6 MEDIUMNozomi Networks via NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses DJI Mavic 3 Wi-Fi Weak Credentials / QuickTransfer Key Derivation (CVE-2023-6951) at CRITICAL — the worst of 2 risk paths (perception). The dominant consequence is exposure of sensor or biometric data.

Vulnerability

DJI Mavic 3 Wi-Fi Weak Credentials / QuickTransfer Key Derivation (CVE-2023-6951). Reported attack vector: Adjacent network (drone Wi-Fi range).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

PERCEPTION_PRIVACYCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:4/EX:2/PH:0/DP:4/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLE

Exposure EX=2 (reachability-bound) · bands PH=MONITOR · DP=CRITICAL · AT=ELEVATED → base CRITICAL · caps privacy-only cap → assessed CRITICAL.

  • RE2 — adjacent Wi-Fi RF proximity (AV:A) plus operator using QuickTransfer (UI:R).
  • EC4 — AC:L single-step PSK derivation from predictable inputs once known.
  • DP4 — decrypted live drone telemetry/media = camera/nav/spatial perception state of an autonomous vehicle.
  • perception_feeds_action — false: attacker only observes (C:H, I:N, A:N); no demonstrated injection back into flight/nav decisions.
  • AT2 — bounded unauthorized access to drone network services, no control-plane/admin authority, no I/A impact.
  • PH0 — no actuation/safety effect demonstrated.
  • CH2 — + boundary_crossing: crosses app/device/RF boundary (joins device net, decrypts operator-device traffic) but no demonstrated cross-domain authority transfer.
  • SR4 — weak key derivation is systematic across the affected model/firmware list (shared derivation scheme = portable technique).
  • SX2 — per-device proximity-bound, must be in RF range of each target, not fleet-remote.
  • OR2 — firmware update fixes it, no recall/key rotation across fleet.
  • EV2 — report-backed (Nozomi writeup), LS PATCH_AVAILABLE. Not known exploited in wild.

DATA_PRIVACYHIGH

CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:4/EX:2/PH:0/DP:3/AT:2/CH:2/SR:4/SX:2/OR:2/EV:2/LS:PATCH_AVAILABLE

Exposure EX=2 (reachability-bound) · bands PH=MONITOR · DP=HIGH · AT=ELEVATED → base HIGH · caps privacy-only cap → assessed HIGH.

  • Distinct terminal consequence: confidentiality of transferred media/files and exposure of drone network services (foothold), separate from live perception interception.
  • RE2 — Wi-Fi range + operator QuickTransfer in use (AV:A, UI:R).
  • EC4 — AC:L derive-PSK-and-join.
  • DP3 — transferred media/recorded content and exposed service/op-state = sensitive proprietary/PII-class data rather than live world-model feed.
  • AT2 — bounded network access to drone services, confidentiality-only, no admin/firmware/command authority (I:N, A:N).
  • PH0 — no safety/physical effect.
  • CH2 — + boundary_crossing: app-to-device-network-to-RF boundary crossing, foothold on services, but no demonstrated authority pivot to control.
  • SR4 — derivation weakness reusable across affected firmware/models.
  • SX2 — proximity-bound per target, not remote fleet mass-exploit.
  • OR2 — vendor firmware update remedies.
  • EV2 — report-backed, LS PATCH_AVAILABLE, no in-the-wild exploitation.

Published baseline

  • v3.1 6.6 MEDIUM — CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N — Nozomi Networks via NVD

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0020 (“DJI Mavic 3 Wi-Fi Weak Credentials / QuickTransfer Key Derivation (CVE-2023-6951)”), paths.cfse.ai/CPATH-2026-0020 (published 2026-06-03).