Executive brief
Daktronics digital media controllers, used to manage large-scale electronic displays and scoreboards, contain a security flaw that allows unauthorized access to the underlying file system. An attacker could exploit this to view sensitive files or gain full administrative control over the device. This could lead to unauthorized content being displayed, service outages, or the device being used as a foothold for further network attacks.
Technical details
A path traversal vulnerability (CWE-22) exists in multiple versions of Daktronics Controller Firmware (VFC-DMP-5000, DMP-5000, and DMP-8000). The flaw allows both authenticated and unauthenticated remote attackers to bypass directory restrictions by using manipulated file paths. Successful exploitation enables an attacker to enumerate and access arbitrary files on the system, which, according to the advisory, can lead to full root-level access and system control. This vulnerability is part of a set of issues including hard-coded credentials and unrestricted file uploads. Users are advised to update to versions 8.117.0.x, 9.43.0.x, or 10.34.0.x depending on their hardware configuration.
Affected products
- Daktronics VFC-DMP-5000 < v8.117.x.x, < v9.43.x.x, < v10.34.x.x
- Daktronics DMP-5000 < v8.117.x.x, < v9.43.x.x, < v10.34.x.x
- Daktronics DMP-8000 < v8.117.x.x, < v9.43.x.x, < v10.34.x.x
Timeline
- 2026-06-25: advisory: Initial publication of ICSA-26-176-04 by CISA
- 2026-06-26: disclosed: CVE-2026-28701 published to NVD