CVE-2026-28701
PUBLISHED
Published: 26 Jun 2026, 22:40
Last modified:26 Jun 2026, 23:03
Vulnerability Summary
Overall Risk (default)
high
70/100 CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
26 Jun 2026, 22:40
Published
Vulnerability first disclosed
26 Jun 2026, 23:03
Last Modified
Vulnerability information updated
Description
Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.
CVSS Metrics
- v4.0•CRITICAL•Score: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Techniques & Countermeasures
- CWE-22•Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Affected Systems
- daktronics•dmp-5000
< v10.34.x.x | < v8.117.x.x | < v9.43.x.x
- daktronics•dmp-8000
< v10.34.x.x | < v8.117.x.x | < v9.43.x.x
- daktronics•vfc-dmp-5000
< v8.117.x.x | < v9.43.x.x | < v10.34.x.x