CVE-2026-31928: Daktronics Controller Firmware Use of Hard-coded Credentials
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Daktronics Controller Firmwareto a version that resolves this vulnerability.Fixed in 8.117.0.x - Upgrade
Upgrade
Daktronics Controller Firmwareto a version that resolves this vulnerability.Fixed in 9.43.0.x - Upgrade
Upgrade
Daktronics Controller Firmwareto a version that resolves this vulnerability.Fixed in 10.34.0.x
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31928?
The severity of CVE-2026-31928 is high, rated at 8.1.
How do I fix CVE-2026-31928?
To fix CVE-2026-31928, change the default administrative credentials on the Daktronics DMP-5000 devices.
What are the risks associated with CVE-2026-31928?
CVE-2026-31928 poses risks of unauthorized full system access due to hard-coded credentials and weak authentication controls.
Is CVE-2026-31928 easy to exploit?
Yes, CVE-2026-31928 can be easily exploited if the hard-coded default credentials are not changed.
What type of devices are affected by CVE-2026-31928?
CVE-2026-31928 affects the Daktronics DMP-5000 devices.