The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.
Metrics
Affected Vendors & Products
References
History
Mon, 29 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Daktronics
Daktronics dmp-5000 Daktronics dmp-8000 Daktronics vfc-dmp-5000 |
|
| Vendors & Products |
Daktronics
Daktronics dmp-5000 Daktronics dmp-8000 Daktronics vfc-dmp-5000 |
Mon, 29 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Jun 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server. | |
| Title | Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published: 2026-06-26T22:48:56.236Z
Updated: 2026-06-29T13:15:20.091Z
Reserved: 2026-03-30T20:11:42.801Z
Link: CVE-2026-33560
Updated: 2026-06-29T13:15:16.552Z
No data.
No data.