CVE 8.1 HIGH

Daktronics Controller Firmware Use of Hard-coded Credentials_CVE-2026-31928

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.

Basic Information

ID CVE-2026-31928
Source icscert
Published Jun 26, 2026 at 22:52

Affected Product

Vendor Daktronics
Product VFC-DMP-5000
Affected Versions Daktronics VFC-DMP-5000 0
Daktronics VFC-DMP-5000 0
Daktronics VFC-DMP-5000 0
Daktronics DMP-5000 0
Daktronics DMP-5000 0
Daktronics DMP-5000 0
Daktronics DMP-8000 0
Daktronics DMP-8000 0
Daktronics DMP-8000 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.