CVE-2026-28701: Daktronics Dmp-5000 Firmware
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.
Affected products
- Daktronics Dmp-5000 Firmware: before 8.117.0.0 (fixed in 8.117.0.0); from 9.0.0.0, before 9.43.0.0 (fixed in 9.43.0.0); from 10.0.0.0, before 10.34.0.0 (fixed in 10.34.0.0)
- Daktronics Dmp-8000 Firmware: before 8.117.0.0 (fixed in 8.117.0.0); from 9.0.0.0, before 9.43.0.0 (fixed in 9.43.0.0); from 10.0.0.0, before 10.34.0.0 (fixed in 10.34.0.0)
- Daktronics Vfc-Dmp-5000 Firmware: before 8.117.0.0 (fixed in 8.117.0.0); from 9.0.0.0, before 9.43.0.0 (fixed in 9.43.0.0); from 10.0.0.0, before 10.34.0.0 (fixed in 10.34.0.0)
Published 2026-06-26. Last modified 2026-07-06.