CVE-2026-33560 Details
Description
The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.
A vulnerability exists in the Daktronics DMP-5000 file service, allowing authenticated users to upload files of any type without proper validation. This unrestricted file upload capability can be exploited to upload executable binaries and scripts, which are then written directly to the server. The issue arises from a lack of file extension filtering and content inspection on the uploaded files.
Users are advised to update their device software to version 8.117.0.x, 9.43.0.x, or 10.34.0.x, depending on their product configuration. Additionally, it is recommended to change default passwords to strong, unique credentials for each device.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-04.json | [email protected] | Third Party Advisory |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-04 | [email protected] | Third Party AdvisoryUS Government Resource |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| daktronics dmp-5000 firmware | < 8.117.0.0 >= 9.0.0.0, < 9.43.0.0 >= 10.0.0.0, < 10.34.0.0 |
CPE
Remediation
| |
| daktronics dmp-5000 | All versions |
CPE
Remediation
| |
| daktronics dmp-8000 firmware | < 8.117.0.0 >= 9.0.0.0, < 9.43.0.0 >= 10.0.0.0, < 10.34.0.0 |
CPE
Remediation
| |
| daktronics dmp-8000 | All versions |
CPE
Remediation
| |
| daktronics vfc-dmp-5000 firmware | < 8.117.0.0 >= 9.0.0.0, < 9.43.0.0 >= 10.0.0.0, < 10.34.0.0 |
CPE
Remediation
| |
| daktronics vfc-dmp-5000 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | Initial Analysis | [email protected] |
| Jun 29, 2026 | CVE Modified | CISA-ADP |
| Jun 26, 2026 | New CVE Received | [email protected] |