By vendor
Daktronics vulnerabilities
Known CVEs affecting Daktronics products, prioritized by severity, with SEC.co remediation and detection guidance.
2 published vulnerabilities
- CVE-2026-31928HIGH 8.1
Daktronics DMP-5000, DMP-8000, and VFC-DMP-5000 devices ship with preset administrative accounts that use weak or default credentials. These accounts grant complete system control and cannot be disabled during initial setup or normal operation. An authenticated attacker with network access can exploit these weak credentials to take full control of affected displays and related infrastructure.
- CVE-2026-33560HIGH 7.1
The DMP-5000 file service and related Daktronics display products contain a critical flaw in their file upload mechanism. Authenticated users can upload any type of file—including executable programs and scripts—without restriction. The system fails to validate file types, inspect content, or enforce any filtering, allowing attackers with valid credentials to place malicious binaries directly onto the server where they can potentially be executed.