High severity8.1NVD Advisory· Published Jun 26, 2026· Updated Jul 6, 2026
CVE-2026-31928
CVE-2026-31928
Description
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.
Affected products
5- cpe:2.3:o:daktronics:vfc-dmp-5000_firmware:*:*:*:*:*:*:*:*Range: <8.117.0.0
Patches
Vulnerability mechanics
References
2- github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-04.jsonnvdThird Party Advisory
- www.cisa.gov/news-events/ics-advisories/icsa-26-176-04nvdThird Party AdvisoryUS Government Resource
News mentions
2- ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreThe Hacker News · Jul 6, 2026
- Daktronics Controller FirmwareCISA ICS Advisories