Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-31928: DMP-5000 devices have a default admin account with weak security

CVE-2026-31928
Summary

DMP-5000 security devices come with a default admin account that isn't changed during setup. This allows unauthorized access to the device's system. To fix this, change the admin account password immediately after setup.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
daktronics dmp-5000_firmware < 8.117.0.0
>= 9.0.0.0, < 9.43.0.0
>= 10.0.0.0, < 10.34.0.0
cpe:2.3:o:daktronics:dmp-5000_firmware:*:*:*:*:*:*:*:*
daktronics dmp-8000_firmware < 8.117.0.0
>= 9.0.0.0, < 9.43.0.0
>= 10.0.0.0, < 10.34.0.0
cpe:2.3:o:daktronics:dmp-8000_firmware:*:*:*:*:*:*:*:*
daktronics vfc-dmp-5000_firmware < 8.117.0.0
>= 9.0.0.0, < 9.43.0.0
>= 10.0.0.0, < 10.34.0.0
cpe:2.3:o:daktronics:vfc-dmp-5000_firmware:*:*:*:*:*:*:*:*
Original title
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using t...
Original description
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.
nvd CVSS3.1 8.1
nvd CVSS4.0 9.3
Vulnerability type
CWE-798 Use of Hard-coded Credentials
Published: 26 Jun 2026 · Updated: 23 Jul 2026 · First seen: 26 Jun 2026