Junglewise Threat Intelligence

CVE-2026-31928: Daktronics DMP-5000 hard-coded default credentials

CVE-2026-31928 · Severity: high · CVSS 8.1 · Published 2026-06-26

Technologies: Daktronics DMP-8000, Daktronics VFC-DMP-5000, Daktronics DMP-5000. Vendors: Daktronics.

Executive brief

Daktronics DMP-5000 and DMP-8000 digital media players, used for large-scale displays and signage, are shipped with default administrative credentials that are not required to be changed. An attacker who knows these default credentials can gain full administrative control over the device. This could lead to unauthorized content display, service disruption, or a foothold for further network attacks.

Technical details

The vulnerability is classified as Use of Hard-coded Credentials (CWE-798) within the Daktronics DMP-5000 and DMP-8000 controller firmware. The devices ship with a default administrative web account with weak authentication controls that are not required to be changed during initial setup. A remote attacker with network access to the administrative interface can use these credentials to gain full system access. While the CVSS 3.1 vector indicates low privileges (PR:L), the impact is high for confidentiality and integrity (C:H/I:H). Daktronics has released firmware updates (8.117.0.x, 9.43.0.x, and 10.34.0.x) to address this and recommends users immediately change default passwords.

Affected products

  • Daktronics VFC-DMP-5000 <v8.117.x.x, <v9.43.x.x, <v10.34.x.x
  • Daktronics DMP-5000 <v8.117.x.x, <v9.43.x.x, <v10.34.x.x
  • Daktronics DMP-8000 <v8.117.x.x, <v9.43.x.x, <v10.34.x.x

Timeline

  • 2026-06-25: advisory: Initial publication by CISA (ICSA-26-176-04)
  • 2026-06-26: disclosed: NVD publication date

References

Related threats