CVE-2026-28701

PUBLISHED
Published: 26 Jun 2026, 22:40
Last modified:26 Jun 2026, 23:03

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Jun 2026, 22:40
Published
Vulnerability first disclosed
26 Jun 2026, 23:03
Last Modified
Vulnerability information updated

Description

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.

CVSS Metrics

  • v4.0CRITICALScore: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • daktronicsdmp-5000

    < v10.34.x.x | < v8.117.x.x | < v9.43.x.x

  • daktronicsdmp-8000

    < v10.34.x.x | < v8.117.x.x | < v9.43.x.x

  • daktronicsvfc-dmp-5000

    < v8.117.x.x | < v9.43.x.x | < v10.34.x.x

References (2)