Parrot Anafi Drone: RCE via Network Protocol Reverse Engineering

2025-01-01

Security researchers reverse-engineered the Wi-Fi communication protocol between a Parrot Anafi drone and its controller. Using ARP spoofing, they intercepted packets related to takeoff and landing sequences, identifying the crucial payload structure. A simple Python script was created to send these packets, enabling remote control of the drone's takeoff and landing without the official controller. This revealed a vulnerability allowing attackers to interfere with the drone's operation, such as preventing takeoff or landing.

Read more