# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 28 February 2026 |
| Platform | Quiet Systems |
| Series | DKSR-M-2026-02 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

Legacy DJI Enhanced-WiFi pairing gets a capture-replay CVE. Same leftover fleet as CVE-2025-10250. Vendor did not respond, per the CVE.

### Key judgments

1. **[Assessment — High confidence]** CVE-2026-1743, NVD 1 February 2026, Mini/Air/Spark/Mini SE through 01.00.0500.
2. **[Assessment — High confidence]** This is not current OcuSync.
3. **[Uncertainty]** CVE states exploit disclosed; this filing does not reproduce it.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. CVE-2026-1743: DJI Enhanced-WiFi pairing capture-replay

*Event / publication dates: NVD 1 February 2026*

| Field | Value |
| --- | --- |
| Component | firmware |
| Product | DJI Mavic Mini, Air, Spark, Mini SE up to 01.00.0500 |
| CVE / advisory | CVE-2026-1743 |
| Patch | none recorded; vendor contacted, no response (CVE text) |
| Exploit status | catalogued |
| Taxonomy | CAPEC-115 · ATT&CK ICS T0860 · OWASP IoT I1 |

**Verified record — [Fact — A1] https://nvd.nist.gov/vuln/detail/CVE-2026-1743**

**Exposure.** Pairing authentication bypass by capture-replay. Local network, high complexity.

**Intelligence assessment.** [Assessment — High confidence] Sibling to 2025-09 hard-coded key and 2026-03 DoS. [Inference — Moderate confidence] Leftover fleet still flies; Passport must mark Enhanced-WiFi as unsupported.

**Opportunity.** Do not fold into Mavic 3 / Matrice QuickTransfer. Different radio.

**LRRK relevance.** Control Fabric on leftover SKUs.

**Confidence.** High on CVE/date.

## Forward indicators

1. CVE-2026-26673 Enhanced-WiFi DoS (March).
2. Any vendor statement (none at collection).

> **Collection integrity.** Status only. Earlier “snippet-only” caution is lifted: NVD page exists. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
