The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.
References
| Link | Resource |
|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-176-04.json | Third Party Advisory |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-04 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
History
No history.
Information
Published : 2026-06-26 23:17
Updated : 2026-07-06 17:53
NVD link : CVE-2026-33560
Mitre link : CVE-2026-33560
CVE.ORG link : CVE-2026-33560
JSON object : View
Products Affected
daktronics
- dmp-8000
- dmp-5000
- vfc-dmp-5000_firmware
- dmp-5000_firmware
- vfc-dmp-5000
- dmp-8000_firmware
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
