CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Daktronics Controller Firmware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 271

As cited

Copy frozen at (site build).

vulnerabilities

Daktronics Controller Firmware

Daktronics Controller Firmware for multiple DMP series devices contains three vulnerabilities that could allow unauthorized access and control of affected systems. The issues include path traversal enabling file system enumeration, unrestricted file upload without validation, and default administrative credentials with weak authentication. Daktronics recommends updating to patched firmware versions (8.117.0.x, 9.43.0.x, or 10.34.0.x) and changing default passwords.

Why it matters: Unauthenticated users can achieve root-level access to critical infrastructure controllers used in commercial facilities, emergency services, and healthcare environments worldwide.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Daktronics Controller Firmware

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Daktronics Controller Firmware

Daktronics Controller Firmware contains multiple critical vulnerabilities, including path traversal (CVE-2026-28701), unrestricted file upload (CVE-2026-33560), and hard-coded credentials (CVE-2026-31928), which could grant unauthenticated users root-level system access. Affected versions span VFC-DMP-5000, DMP-5000, and DMP-8000 models below 8.117.x.x, 9.43.x.x, or 10.34.x.x. Daktronics advises updating to patched versions and changing default credentials.

Why it matters: Operators of Daktronics display controllers in commercial, healthcare, and emergency services sectors face remote code execution and full system compromise risk; apply patches and rotate credentials immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Daktronics Controller Firmware

Daktronics Controller Firmware contains multiple critical vulnerabilities, including path traversal (CVE-2026-28701), unrestricted file upload (CVE-2026-33560), and hard-coded credentials (CVE-2026-31928), which could grant unauthenticated users root-level system access. Affected versions span VFC-DMP-5000, DMP-5000, and DMP-8000 models below 8.117.x.x, 9.43.x.x, or 10.34.x.x. Daktronics advises updating to patched versions and changing default credentials.

Why it matters: Operators of Daktronics display controllers in commercial, healthcare, and emergency services sectors face remote code execution and full system compromise risk; apply patches and rotate credentials immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary