CVE-2026-33560
The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.
Published:Jun 26, 2026
Last Modified:Jun 29, 2026
EPS:Jun 26, 2026
EPSS Score:0.00341
CVSS Score:7.1
Affected Products
Vendor
Product
Action
Vendor
Daktronics
Product
Dmp-5000
Daktronics
Dmp-5000
Vendor
Daktronics
Product
Dmp-8000
Daktronics
Dmp-8000
Vendor
Daktronics
Product
Vfc-dmp-5000
Daktronics
Vfc-dmp-5000
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
