As cited
Copy frozen at (site build).
vulnerabilities
Daktronics Controller Firmware
Daktronics Controller Firmware for multiple DMP series devices contains three vulnerabilities that could allow unauthorized access and control of affected systems. The issues include path traversal enabling file system enumeration, unrestricted file upload without validation, and default administrative credentials with weak authentication. Daktronics recommends updating to patched firmware versions (8.117.0.x, 9.43.0.x, or 10.34.0.x) and changing default passwords.
Why it matters: Unauthenticated users can achieve root-level access to critical infrastructure controllers used in commercial facilities, emergency services, and healthcare environments worldwide.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Daktronics Controller Firmware
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Daktronics Controller Firmware
Daktronics Controller Firmware contains multiple critical vulnerabilities, including path traversal (CVE-2026-28701), unrestricted file upload (CVE-2026-33560), and hard-coded credentials (CVE-2026-31928), which could grant unauthenticated users root-level system access. Affected versions span VFC-DMP-5000, DMP-5000, and DMP-8000 models below 8.117.x.x, 9.43.x.x, or 10.34.x.x. Daktronics advises updating to patched versions and changing default credentials.
Why it matters: Operators of Daktronics display controllers in commercial, healthcare, and emergency services sectors face remote code execution and full system compromise risk; apply patches and rotate credentials immediately.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Daktronics Controller Firmware
Daktronics Controller Firmware contains multiple critical vulnerabilities, including path traversal (CVE-2026-28701), unrestricted file upload (CVE-2026-33560), and hard-coded credentials (CVE-2026-31928), which could grant unauthenticated users root-level system access. Affected versions span VFC-DMP-5000, DMP-5000, and DMP-8000 models below 8.117.x.x, 9.43.x.x, or 10.34.x.x. Daktronics advises updating to patched versions and changing default credentials.
Why it matters: Operators of Daktronics display controllers in commercial, healthcare, and emergency services sectors face remote code execution and full system compromise risk; apply patches and rotate credentials immediately.
- Source published
- First seen by Cybersecurity Tracker