# Critical Daktronics Controller Vulnerabilities Expose Emergency Services, Hospitals, and Public Infrastructure to Unauthenticated Compromise
## The Threat
Daktronics Controller Firmware powering digital signage and display systems across hospitals, emergency services, and commercial facilities is vulnerable to a chained attack that grants complete unauthenticated root-level access to affected systems. The vulnerabilities, identified across three critical CVEs, allow threat actors to bypass authentication, traverse restricted directories, and upload malicious executables directly to compromised devices.
Daktronics controllers manage visual information systems in some of the most critical settings in North America — emergency operations centers relay real-time incident data, hospitals display patient information and alerts, and public facilities communicate urgent announcements. A successful compromise of these systems could disrupt emergency response coordination, manipulate critical health information displays, or broadcast false information to the public.
The advisory, published by CISA and Daktronics, underscores a persistent industry problem: widely deployed embedded systems that ship with default credentials and lack basic input validation. These devices often operate on networks protected only by perimeter security, with organizations assuming that internal network access equals trusted access. In modern threat landscapes, that assumption is dangerously outdated.
## Severity and Impact
| CVE | CWE | Title | CVSS 3.1 | CVSS 4.0 | Attack Vector | Authentication | Impact |
|---------|---------|-----------|--------------|--------------|-------------------|--------------------|-----------|
| CVE-2026-28701 | CWE-22 | Path Traversal | 7.7 (HIGH) | 9.3 (CRITICAL) | Local / Network | None Required | Read arbitrary files, enumerate filesystem |
| CVE-2026-33560 | CWE-434 | Unrestricted File Upload | 7.1 (HIGH) | 8.4 (HIGH) | Network | Authenticated | Upload and execute arbitrary binaries |
| CVE-2026-31928 | CWE-798 | Hard-Coded Credentials | N/A | N/A | Network | Default Admin Account | Full system access without authentication |
Vector Strings:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N → v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N → v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:NThe CVSS 4.0 scores represent a significant escalation in severity compared to version 3.1 assessments, reflecting the broader attack surface and the potential for complete system compromise without authentication.
## Affected Products
Daktronics Controller Firmware is deployed across three primary hardware platforms, each with affected versions spanning multiple firmware branches:
VFC-DMP-5000 (Video Flex Controller)
DMP-5000 (Display Management Platform)
DMP-8000 (Enterprise Display Management Platform)
Organizations should determine which firmware branch their systems run and compare against the version numbers above. Devices on legacy branches (8.x) may see extended support timelines; those on newer branches (10.x) should update immediately.
## Mitigations
Immediate Actions (Within 24 Hours):
1. Firmware Update — Apply the appropriate patched version based on your current firmware branch:
- Branch 8: Update to 8.117.0.x or later
- Branch 9: Update to 9.43.0.x or later
- Branch 10: Update to 10.34.0.x or later
Contact Daktronics support for firmware images and update procedures specific to your deployment model.
2. Change Default Credentials — If devices remain unpatched, immediately change the default administrative web account passwords to strong, organization-unique credentials. Do not reuse passwords across devices. Document these changes in a secure credential management system.
3. Network Segmentation — Isolate Daktronics controllers on dedicated VLANs separate from general corporate networks and critical infrastructure segments. Restrict outbound traffic and enforce ingress filtering at network boundaries.
4. Access Control — Implement network access controls limiting administration of these devices to dedicated management workstations. Require multi-factor authentication for any remote management interfaces.
Ongoing Hardening:
## References
- https://nvd.nist.gov/vuln/detail/CVE-2026-28701
- https://nvd.nist.gov/vuln/detail/CVE-2026-33560
- https://nvd.nist.gov/vuln/detail/CVE-2026-31928
- https://cwe.mitre.org/data/definitions/22.html (Path Traversal)
- https://cwe.mitre.org/data/definitions/434.html (Unrestricted File Upload)
- https://cwe.mitre.org/data/definitions/798.html (Hard-Coded Credentials)
---
## HackWire Analysis
This advisory marks the continuation of a troubling pattern in embedded infrastructure: vendors shipping widely deployed systems with default credentials and missing basic input validation, then taking years to address exploitation paths. Daktronics controllers operate in settings where information integrity is mission-critical — a compromised display in an emergency operations center during an active incident could delay response coordination; manipulated patient information displays in hospitals could create liability and safety risks.
What's particularly concerning is the chained nature of these vulnerabilities. An attacker with network access doesn't need to know the default credentials to exploit CVE-2026-28701 (path traversal) to enumerate the filesystem and identify configuration files, potentially extracting credentials or API tokens. Alternatively, an attacker can use the path traversal flaw to locate upload endpoints, then chain to CVE-2026-33560 (unrestricted file upload) using harvested credentials. For organizations that *have* changed defaults, the path traversal vulnerability alone allows unauthenticated directory enumeration — a significant information disclosure. The hard-coded credentials flaw (CVE-2026-31928) for systems running older firmware represents an immediate compromise vector requiring no technical sophistication to exploit.
The firmware branches affected (8.x through 10.x) span systems deployed over the past 5-7 years. Many organizations running these devices are in regulated industries (healthcare, emergency services) where testing and validation of firmware updates on critical infrastructure involves substantial coordination. The advisory provides clear remediation paths, but the timeline for actual patching across thousands of installed systems will stretch months — during which these vulnerabilities remain exploitable. Organizations unable to patch immediately must treat network isolation as non-negotiable.
For defenders, this serves as a reminder to audit embedded systems for outdated firmware versions and to inventory default credentials across all infrastructure — not just servers and endpoints. The presence of these vulnerabilities in systems controlling public-facing displays also creates a vector for information warfare: if attackers can compromise signage in emergency services or hospitals, they can broadcast false alerts or block legitimate communications. — HackWire Editorial
## Related Coverage