The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.

Project Subscriptions

Vendors Products
Daktronics Subscribe
Dmp-5000 Subscribe
Dmp-8000 Subscribe
Vfc-dmp-5000 Subscribe
Advisories

No advisories yet.

Fixes

Solution

Daktronics recommends users update their device software to one of the following versions (based on product configuration in use): 8.117.0.x, 9.43.0.x, or 10.34.0.x


Workaround

Daktronics recommends updating the default passwords and encourages using strong, unique credentials per device.

History

Mon, 29 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Daktronics
Daktronics dmp-5000
Daktronics dmp-8000
Daktronics vfc-dmp-5000
Vendors & Products Daktronics
Daktronics dmp-5000
Daktronics dmp-8000
Daktronics vfc-dmp-5000

Mon, 29 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 26 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.
Title Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-06-29T13:15:20.091Z

Reserved: 2026-03-30T20:11:42.801Z

Link: CVE-2026-33560

cve-icon Vulnrichment

Updated: 2026-06-29T13:15:16.552Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-29T20:06:05Z

Weaknesses