Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type
Summary
| CVE | CVE-2026-33560 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-26 23:17:08 UTC |
| Updated | 2026-06-26 23:17:08 UTC |
| Description | The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server. |
Risk And Classification
Primary CVSS: v4.0 8.4 HIGH from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-434 | CWE-434 CWE-434
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 8.4 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.4 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N |
| 3.1 | [email protected] | Secondary | 7.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
| 3.1 | CNA | CVSS | 7.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Daktronics | VFC-DMP-5000 | affected v8.117.x.x custom | Not specified |
| CNA | Daktronics | VFC-DMP-5000 | affected v9.43.x.x custom | Not specified |
| CNA | Daktronics | VFC-DMP-5000 | affected v10.34.x.x custom | Not specified |
| CNA | Daktronics | DMP-5000 | affected v10.34.x.x custom | Not specified |
| CNA | Daktronics | DMP-5000 | affected v8.117.x.x custom | Not specified |
| CNA | Daktronics | DMP-5000 | affected v9.43.x.x custom | Not specified |
| CNA | Daktronics | DMP-8000 | affected v10.34.x.x custom | Not specified |
| CNA | Daktronics | DMP-8000 | affected v8.117.x.x custom | Not specified |
| CNA | Daktronics | DMP-8000 | affected v9.43.x.x custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-17... | [email protected] | github.com | |
| www.cisa.gov/news-events/ics-advisories/icsa-26-176-04 | [email protected] | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Thomas Jou of Princeton University reported this vulnerability to CISA. (en)
Additional Advisory Data
Solutions
CNA: Daktronics recommends users update their device software to one of the following versions (based on product configuration in use): 8.117.0.x, 9.43.0.x, or 10.34.0.x
Workarounds
CNA: Daktronics recommends updating the default passwords and encourages using strong, unique credentials per device.