CVE-2026-33560: Daktronics Dmp-5000 Firmware

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.

Affected products

  • Daktronics Dmp-5000 Firmware: before 8.117.0.0 (fixed in 8.117.0.0); from 9.0.0.0, before 9.43.0.0 (fixed in 9.43.0.0); from 10.0.0.0, before 10.34.0.0 (fixed in 10.34.0.0)
  • Daktronics Dmp-8000 Firmware: before 8.117.0.0 (fixed in 8.117.0.0); from 9.0.0.0, before 9.43.0.0 (fixed in 9.43.0.0); from 10.0.0.0, before 10.34.0.0 (fixed in 10.34.0.0)
  • Daktronics Vfc-Dmp-5000 Firmware: before 8.117.0.0 (fixed in 8.117.0.0); from 9.0.0.0, before 9.43.0.0 (fixed in 9.43.0.0); from 10.0.0.0, before 10.34.0.0 (fixed in 10.34.0.0)

Published 2026-06-26. Last modified 2026-07-06.