CVE-2026-31928: Daktronics Dmp-5000 Firmware
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.
Affected products
- Daktronics Dmp-5000 Firmware: before 8.117.0.0 (fixed in 8.117.0.0); from 9.0.0.0, before 9.43.0.0 (fixed in 9.43.0.0); from 10.0.0.0, before 10.34.0.0 (fixed in 10.34.0.0)
- Daktronics Dmp-8000 Firmware: before 8.117.0.0 (fixed in 8.117.0.0); from 9.0.0.0, before 9.43.0.0 (fixed in 9.43.0.0); from 10.0.0.0, before 10.34.0.0 (fixed in 10.34.0.0)
- Daktronics Vfc-Dmp-5000 Firmware: before 8.117.0.0 (fixed in 8.117.0.0); from 9.0.0.0, before 9.43.0.0 (fixed in 9.43.0.0); from 10.0.0.0, before 10.34.0.0 (fixed in 10.34.0.0)
Published 2026-06-26. Last modified 2026-07-06.