CVE-2026-33560: CWE-434 in Daktronics VFC-DMP-5000
The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.
AI Analysis
Technical Summary
The Daktronics VFC-DMP-5000 file service exposes endpoints that permit authenticated users to upload arbitrary files without any validation or filtering. This lack of file extension and content inspection allows potentially malicious executable binaries and scripts to be uploaded and stored on the server, which could lead to unauthorized code execution or compromise of the system. The vulnerability is identified as CWE-434 (Unrestricted Upload of File with Dangerous Type). The CVSS v3.1 base score is 7.1, reflecting network attack vector, low attack complexity, required privileges, no user interaction, unchanged scope, low confidentiality impact, high integrity impact, and no availability impact. No patch or official remediation is currently documented, and no known exploits are reported in the wild.
Potential Impact
The vulnerability allows authenticated users to upload arbitrary files, including executable binaries and scripts, without restriction. This can lead to high integrity impact by enabling attackers to execute unauthorized code or modify system behavior. Confidentiality impact is low, and availability is not affected. Exploitation requires valid authentication but no user interaction. The lack of file validation increases the risk of system compromise or persistent malicious code deployment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict authenticated user permissions to only trusted users and monitor file uploads closely. Consider implementing external controls such as network segmentation or file integrity monitoring to detect unauthorized uploads. Avoid exposing the file upload service to untrusted users. Follow vendor advisories for updates on patches or official mitigations.
CVE-2026-33560: CWE-434 in Daktronics VFC-DMP-5000
Description
The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.
CVSS v3.1
Score 7.1high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Daktronics VFC-DMP-5000 file service exposes endpoints that permit authenticated users to upload arbitrary files without any validation or filtering. This lack of file extension and content inspection allows potentially malicious executable binaries and scripts to be uploaded and stored on the server, which could lead to unauthorized code execution or compromise of the system. The vulnerability is identified as CWE-434 (Unrestricted Upload of File with Dangerous Type). The CVSS v3.1 base score is 7.1, reflecting network attack vector, low attack complexity, required privileges, no user interaction, unchanged scope, low confidentiality impact, high integrity impact, and no availability impact. No patch or official remediation is currently documented, and no known exploits are reported in the wild.
Potential Impact
The vulnerability allows authenticated users to upload arbitrary files, including executable binaries and scripts, without restriction. This can lead to high integrity impact by enabling attackers to execute unauthorized code or modify system behavior. Confidentiality impact is low, and availability is not affected. Exploitation requires valid authentication but no user interaction. The lack of file validation increases the risk of system compromise or persistent malicious code deployment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict authenticated user permissions to only trusted users and monitor file uploads closely. Consider implementing external controls such as network segmentation or file integrity monitoring to detect unauthorized uploads. Avoid exposing the file upload service to untrusted users. Follow vendor advisories for updates on patches or official mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- icscert
- Date Reserved
- 2026-03-30T20:11:42.801Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a3f097a27e9c79719196f9a
Added to database: 06/26/2026, 23:21:30 UTC
Last enriched: 07/04/2026, 22:17:31 UTC
Last updated: 08/09/2026, 12:41:10 UTC
Views: 101
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.