The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.
History

Mon, 29 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Daktronics
Daktronics dmp-5000
Daktronics dmp-8000
Daktronics vfc-dmp-5000
Vendors & Products Daktronics
Daktronics dmp-5000
Daktronics dmp-8000
Daktronics vfc-dmp-5000

Mon, 29 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 26 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.
Title Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2026-06-26T22:48:56.236Z

Updated: 2026-06-29T13:15:20.091Z

Reserved: 2026-03-30T20:11:42.801Z

Link: CVE-2026-33560

cve-icon Vulnrichment

Updated: 2026-06-29T13:15:16.552Z

cve-icon NVD

No data.

cve-icon Redhat

No data.