CVE-2026-28701 Details
Description
Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.
A vulnerability exists in various versions of Daktronics Controller Firmware, specifically in the VFC-DMP-5000 and DMP-5000 series, as well as the DMP-8000 series, all prior to certain patched versions. This vulnerability could allow both authenticated and unauthenticated remote users to escape the intended directory restrictions and enumerate arbitrary file system paths. Successful exploitation could grant an unauthenticated user complete root-level access and control of the system.
Users are advised to update their device software to version 8.117.0.x, 9.43.0.x, or 10.34.0.x, depending on the product configuration in use. Additionally, it is recommended to change default passwords and use strong, unique credentials for each device.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-04.json | [email protected] | Third Party Advisory |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-04 | [email protected] | Third Party AdvisoryUS Government Resource |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| daktronics dmp-5000 firmware | < 8.117.0.0 >= 9.0.0.0, < 9.43.0.0 >= 10.0.0.0, < 10.34.0.0 |
CPE
Remediation
| |
| daktronics dmp-5000 | All versions |
CPE
Remediation
| |
| daktronics dmp-8000 firmware | < 8.117.0.0 >= 9.0.0.0, < 9.43.0.0 >= 10.0.0.0, < 10.34.0.0 |
CPE
Remediation
| |
| daktronics dmp-8000 | All versions |
CPE
Remediation
| |
| daktronics vfc-dmp-5000 firmware | < 8.117.0.0 >= 9.0.0.0, < 9.43.0.0 >= 10.0.0.0, < 10.34.0.0 |
CPE
Remediation
| |
| daktronics vfc-dmp-5000 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | Initial Analysis | [email protected] |
| Jun 29, 2026 | CVE Modified | CISA-ADP |
| Jun 26, 2026 | New CVE Received | [email protected] |