CVE-2026-28701Patch(daktronics / dmp-5000)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch daktronics dmp-5000 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dmp-5000
  • dmp-5000_firmware
  • dmp-8000
  • dmp-8000_firmware

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Exploit: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-06-26); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
dmp-5000dmp-5000_firmwaredmp-8000dmp-8000_firmwarevfc-dmp-5000vfc-dmp-5000_firmware

1 version affected across 6 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-06-26: 1Mentions · 2026-06-27: 1Mentions · 2026-06-28: 1Mentions · 2026-07-03: 1Patch / Workaround · 2026-06-27: 1Patch / Workaround · 2026-06-28: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-28: 1Technical Details · 2026-07-03: 106-2606-2706-2807-03
Signal classification3 categories
Patch
250.0%
Exploit
125.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-261
Exploit1
2026-06-271
Patch1
2026-06-281
Patch1
2026-07-031
Disclosure1
Full discourse4 posts
  • SecAlerts@SecAlertsCo
    Disclosure

    🏟️ CISA ICS alert: CVE-2026-28701 in Daktronics Controller Firmware. Both authenticated and unauthenticated remote users can traverse directories and enumerate arbitrary file paths. CVSS 9.3 critical. Audit your OT stack. https://secalerts.co/vulnerability/CVE-2026-28701?utm_campaign=x https://t.co/tzQ0UKsrAv

    Post summary

    CISA issues a critical alert for CVE‑2026‑28701 in Daktronics Controller Firmware, noting that authenticated and unauthenticated remote users can traverse directories and enumerate arbitrary file paths (CVSS 9.3).

    0000091
    847 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-28701 (CVSS 9.8) Daktronics Controller Firmware allows authenticated & unauthenticated remote users to escape directories & enumerate file system paths. Path traversal (CWE-22) exploitable over network with no user interaction. Patch immediately. https://t.co/zYKJZXhMEY

    Post summary

    The tweet announces a critical path‑traversal flaw (CVE‑2026‑28701) in Daktronics firmware, urging users to apply the patch immediately.

    0000042
    52 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-28701 (CVSS 9.8) affects Daktronics Controller Firmware, enabling remote directory traversal. Organizations using these systems should verify versions and apply updates. https://nvd.nist.gov/vuln/deta… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/iELyVoR09O

    Post summary

    CVE-2026-28701 is a high‑severity remote directory traversal flaw in Daktronics Controller Firmware; users are urged to check firmware versions and apply vendor updates.

    0000046
    92 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Exploit

    Attackers chaining CVE-2026-31928, CVE-2026-33560, and CVE-2026-28701 can escalate from hard-coded credentials to root access on Daktronics industrial controllers. TRC analysis shows lateral movement through path traversal enabling system-wide compromise. Runtime segmentation helps contain post-compromise activity in critical infrastructure environments. #IndustrialSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/daktronics-controller-firmware-vulnerabilities-2026

    Post summary

    A threat research report explains how attackers can chain CVE-2026-31928, CVE-2026-33560, and CVE-2026-28701 to move from hard‑coded credentials to root on Daktronics controllers, using path traversal for lateral movement and system‑wide compromise.

    0000043
    1.9K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
HWdaktronicsdmp-5000---
OSdaktronicsdmp-5000_firmware---
HWdaktronicsdmp-8000---
OSdaktronicsdmp-8000_firmware---
HWdaktronicsvfc-dmp-5000---
OSdaktronicsvfc-dmp-5000_firmware---

Explore more