Executive brief
Daktronics DMP-5000 and DMP-8000 controllers, which are used to manage digital displays and signage, contain a security flaw in their file service. An authenticated user can upload any type of file, including malicious scripts or executable programs, directly to the server. This could allow an attacker to gain unauthorized control over the display system, potentially leading to the broadcast of unauthorized content or further network intrusion.
Technical details
The vulnerability is classified as Unrestricted Upload of File with Dangerous Type (CWE-434) within the DMP-5000 file service component. Exposed endpoints allow authenticated users to upload files of any type without extension filtering or content inspection. This allows executable binaries and scripts to be written directly to the server's filesystem. While authentication is required, the vulnerability can be combined with other issues like default credentials to achieve significant impact. Daktronics recommends updating firmware to versions 8.117.0.x, 9.43.0.x, or 10.34.0.x depending on the product configuration.
Affected products
- Daktronics VFC-DMP-5000 < v8.117.x.x, < v9.43.x.x, < v10.34.x.x
- Daktronics DMP-5000 < v8.117.x.x, < v9.43.x.x, < v10.34.x.x
- Daktronics DMP-8000 < v8.117.x.x, < v9.43.x.x, < v10.34.x.x
Timeline
- 2026-06-25: advisory: Initial publication by CISA (ICSA-26-176-04)
- 2026-06-26: disclosed: NVD publication date