The Cybersecurity and Infrastructure Security Agency (CISA) published an advisory concerning three critical vulnerabilities in Daktronics' VFC-DMP-5000, DMP-5000, and DMP-8000 controllers. The advisory identifies a path traversal issue exploitable without authentication, an authenticated arbitrary file upload issue, and default administrative credentials that allow full system access. Daktronics has released patches for these vulnerabilities and advised users to change default passwords.
Security researcher Thomas Jou reported the vulnerabilities through CISA's VINCE platform in early January 2026. Jou, an undergraduate at Princeton University, identified multiple internet-exposed controllers susceptible to these issues. He explained, "The path traversal vulnerability allows reading files off the device, which is useful for recon and credential discovery."
Jou further detailed the potential impact, stating, "In practical terms, an attacker could tamper with what the sign displays — loading false or malicious messages on billboards and roadway signage, or fake alerts — up to and including full compromise of the device (though in practice that last step is non-trivial)." Daktronics, an American company specializing in large-scale LED video displays and electronic scoreboards, had patched firmware versions ready by around early March 2026.
Why It Matters
The disclosure of these vulnerabilities involves risks associated with large-scale public display systems. Unauthorized access to Daktronics' controllers could enable tampering with information displayed on billboards, roadway signage, and other dynamic messaging systems. The recommendation to change default passwords addresses a common security oversight, while the deployment of patches aims to mitigate specific technical flaws.
forum Comments (0)
No comments yet. Be the first to comment.