CISA issued an advisory for multiple vulnerabilities in Daktronics VFC-DMP-5000, DMP-5000, and DMP-8000 controllers used to operate highway message boards, roadside signs, digital billboards, and other large LED displays. Reported by researcher Thomas Jou, the flaws include path traversal or path enumeration, unrestricted or arbitrary file upload, and the use of default administrator credentials, which together can allow unauthorized remote access and potentially root-level control of exposed devices.
The researcher found that multiple controllers were reachable from the internet and that many still used default credentials, making remote exploitation and manipulation of displayed content feasible. Daktronics released patched firmware following coordinated disclosure through CISA's VINCE platform, while CISA and reporting on the advisory urged operators to apply updates, change default passwords, and remove direct internet exposure to reduce the risk of compromise.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Researcher Thomas Jou discovered vulnerabilities in internet-exposed Daktronics display controllers and reported them through CISA's VINCE platform in January 2026.
CISA published an advisory describing vulnerabilities in Daktronics display controllers used for highway signs, billboards, and other LED displays, warning that the issues could enable remote compromise and manipulation of devices. The advisory also highlighted mitigations such as changing default credentials and reducing direct internet exposure.
By early March, Daktronics had prepared patched firmware for the affected VFC-DMP-5000, DMP-5000, and DMP-8000 display controllers following coordinated disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcesecurityweek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.