# Critical Vulnerabilities in Daktronics Controllers Put Highway Signs, Billboards at Risk of Remote Hijacking


The infrastructure that guides motorists and advertises to millions of commuters faces a serious security threat. CISA has published an advisory detailing three critical and high-severity vulnerabilities affecting Daktronics controllers that manage large-scale LED displays used on highways, airport terminals, sports venues, and metropolitan billboards worldwide. The flaws could allow unauthenticated attackers to seize complete control of these systems and display false or malicious content to unsuspecting audiences.


## The Threat


According to CISA's advisory, three models of Daktronics display controllers are vulnerable to exploitation:


  • VFC-DMP-5000
  • DMP-5000
  • DMP-8000

  • These controllers are the brains behind some of the most visible digital infrastructure in North America and beyond. A successful attack exploiting these vulnerabilities could result in complete root-level access to the affected system, giving attackers full control over what millions of people see displayed on highways and billboards.


    The vulnerabilities were discovered and reported by Thomas Jou, a cybersecurity researcher and undergraduate student at Princeton University. In field testing, Jou identified multiple internet-exposed controllers actively running vulnerable firmware, meaning they are accessible to attackers anywhere in the world with an internet connection.


    ## Technical Details of the Vulnerabilities


    The three vulnerabilities paint a clear exploitation pathway:


    | Vulnerability | Type | Authentication Required | Risk Level |

    |---|---|---|---|

    | Path Traversal | File System Enumeration | No | Critical |

    | Default Admin Credentials | Weak Authentication | No | Critical |

    | Arbitrary File Upload | Code Injection | Yes (with default creds) | High |


    ### Unauthenticated Path Traversal (CVE details pending)


    The path traversal vulnerability allows an attacker to enumerate arbitrary file system paths without any authentication. This reconnaissance capability is the opening move in most sophisticated attacks. An attacker can use this flaw to:


  • Map the system's directory structure
  • Locate configuration files
  • Discover stored credentials
  • Identify installed software and versions

  • "The path traversal vulnerability allows reading files off the device, which is useful for recon and credential discovery," Jou explained to SecurityWeek.


    ### Default Administrator Credentials


    Perhaps the most dangerous flaw is the presence of hardcoded default administrative credentials that are not required to be changed during initial setup. Jou's research found that "a majority of internet-exposed units were still using" these default credentials in the field. This transforms the reconnaissance gathered from the path traversal flaw into actionable access.


    ### Arbitrary File Upload


    With administrator credentials (either discovered through the path traversal flaw or obtained from default credentials), an attacker can upload arbitrary files to the device. This could include:


  • Modified firmware
  • Malicious scripts
  • False content for display
  • Backdoors for persistent access

  • ## Real-World Impact: From False Messages to Full Compromise


    The practical implications range from nuisance-level attacks to serious public safety concerns:


    Display Tampering: An attacker could load false or malicious messages onto highway signage, potentially:

  • Displaying fake traffic alerts that mislead motorists
  • Showing emergency messages that cause unnecessary panic
  • Broadcasting politically motivated or hateful content
  • Advertising fraudulent services or scams

  • Public Confusion and Safety: Highway dynamic message signs are often used to warn drivers of accidents, road closures, and hazardous conditions. Hijacking these systems could undermine public trust in official alerts and create dangerous confusion during actual emergencies.


    Advertising Fraud: Digital billboards are significant revenue sources for municipalities and advertising companies. An attacker could deface these displays, disrupting campaigns or inserting competitor advertisements.


    Full System Compromise: While Jou noted that "full compromise of the device is non-trivial," the combination of vulnerabilities provides the foundation for persistent, undetectable access to critical infrastructure.


    ## Background: Daktronics' Role in Digital Infrastructure


    Daktronics is a South Dakota-based manufacturer with a dominant position in large-scale LED display systems. The company's products are ubiquitous:


  • Sports venues: Scoreboards and video displays in professional and collegiate arenas
  • Highways: Dynamic message signs that communicate traffic and weather information
  • Airports: Terminal signage and wayfinding displays
  • Urban centers: Metropolitan billboards and information displays
  • Schools: Athletic and informational displays

  • The ubiquity of Daktronics equipment means that vulnerabilities in their controllers could affect critical public-facing systems across the country and globally.


    ## Discovery and Disclosure Timeline


    Jou followed responsible disclosure practices through CISA's VINCE (Vulnerability Information and Coordination Environment) platform:


  • Early January 2026: Vulnerabilities reported through VINCE
  • March 2026: Patched firmware versions ready (approximately 8 weeks later)
  • June 2026: Public advisory and patch release

  • "The vendor was very responsive," Jou told SecurityWeek. "The remaining time before publication was largely coordinated advisory preparation and customer notification."


    Daktronics released patches and advised customers to:

  • Update to patched firmware versions
  • Change default administrator credentials immediately
  • Limit network exposure of controllers to trusted networks only

  • However, the vendor has not publicly responded to additional media inquiries about the scope of affected installations or remediation efforts already underway.


    ## Internet Exposure: A Critical Problem


    One of the most alarming findings from Jou's research is that multiple Daktronics controllers are directly exposed to the internet without any network access controls. While Jou noted that "it's up to Daktronics customers rather than the vendor to ensure their installations are not exposed to the internet," the reality is that many organizations deploy these systems without adequate security architecture.


    This is a common pattern in operational technology (OT) and industrial control systems (ICS): devices are deployed with convenience prioritized over security, and responsibility for network segmentation is often ambiguous between vendor and customer.


    ## Implications for Organizations and Public Safety


    This vulnerability disclosure highlights several systemic issues in critical infrastructure security:


    1. Legacy OT Security: Display controllers may be years old, deployed before security was a primary concern, and operate without regular patching schedules.


    2. Default Credentials in Production: The fact that default credentials remain active on deployed systems suggests inadequate deployment practices and limited security awareness among operators.


    3. Network Segmentation Failures: Internet-exposed controllers indicate that organizations have failed to implement proper network isolation for systems that should never be directly accessible from the public internet.


    4. Vendor Responsibility Ambiguity: The disconnect between vendor security practices and customer deployment practices creates gaps that attackers can exploit.


    ## Recommendations


    For Daktronics Customers:


  • Immediately patch all VFC-DMP-5000, DMP-5000, and DMP-8000 controllers to the latest firmware versions
  • Change all default credentials without delay
  • Audit network access: Verify that controllers are NOT directly accessible from the internet
  • Implement network segmentation: Controllers should reside on isolated OT networks with restricted access
  • Enable logging: Configure detailed logging on all controllers to detect suspicious access
  • Establish an update schedule: Implement regular firmware update cycles rather than ad-hoc patching

  • For Organizations with Similar Systems:


  • Inventory your infrastructure: Identify all remotely controllable displays and signage systems
  • Security audit: Conduct security assessments of OT and ICS devices, particularly those with internet exposure
  • Vendor outreach: Request security advisories and patch timelines from all OT equipment manufacturers
  • Zero-trust architecture: Design network access with the assumption that OT devices should never be internet-facing

  • ---


    ## HackWire Analysis


    This disclosure represents a critical vulnerability in one of America's most visible public-facing infrastructure systems—yet it received limited attention outside of the cybersecurity community. The implications extend far beyond the technical details: a motivated attacker could manipulate the information environment seen by millions of commuters daily, eroding trust in official communications at scale.


    What makes this particularly concerning is the persistence of default credentials in the field. Jou's finding that most internet-exposed controllers were still using factory defaults suggests a failure at multiple organizational levels—from Daktronics' decision not to require credential changes during deployment, to customer organizations that clearly lack basic inventory and configuration management processes for their critical systems.


    The timing is significant: as of June 2026, patches have been available for only a few months. Organizations running these controllers likely had minimal awareness of the vulnerabilities until this public advisory, and adoption of patches across distributed installations—often managed by traffic departments with limited IT resources—will be slow. This creates a window of opportunity for attackers to probe and exploit unpatched systems before most organizations complete remediation.


    The broader pattern is troubling. OT security remains fragmented, with vendors, integrators, and operators each claiming it's "the other guy's responsibility" to ensure secure deployment. Daktronics was appropriately responsive during the disclosure process, but that doesn't change the fact that millions of people depend on systems that can be hijacked by anyone with internet access and ten minutes of reconnaissance. We need regulatory frameworks that assign clear security responsibilities throughout the supply chain and mandate minimum security baselines before devices leave the factory.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Critical Infrastructure](https://www.hackwire.news/category/critical-infrastructure) and [ICS/OT Security](https://www.hackwire.news/category/ics-ot)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)