LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-33560

daktronics · dmp-5000 firmware

Published
CVSS7.1
Severityhigh
WeaknessCWE-434
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

Description

The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-33560

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-33560.