Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.
History

Mon, 29 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Daktronics
Daktronics dmp-5000
Daktronics dmp-8000
Daktronics vfc-dmp-5000
Vendors & Products Daktronics
Daktronics dmp-5000
Daktronics dmp-8000
Daktronics vfc-dmp-5000

Mon, 29 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 26 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Title Daktronics Controller Firmware Path Traversa Daktronics Controller Firmware Path Traversal

Fri, 26 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
Description Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.
Title Daktronics Controller Firmware Path Traversa
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2026-06-26T22:40:03.058Z

Updated: 2026-06-29T13:15:56.672Z

Reserved: 2026-03-30T20:11:42.786Z

Link: CVE-2026-28701

cve-icon Vulnrichment

Updated: 2026-06-29T13:15:53.615Z

cve-icon NVD

No data.

cve-icon Redhat

No data.