Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-31928: DMP-5000 devices have a default admin account with weak security
CVE-2026-31928
Summary
DMP-5000 security devices come with a default admin account that isn't changed during setup. This allows unauthorized access to the device's system. To fix this, change the admin account password immediately after setup.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| daktronics | dmp-5000_firmware |
< 8.117.0.0 >= 9.0.0.0, < 9.43.0.0 >= 10.0.0.0, < 10.34.0.0 cpe:2.3:o:daktronics:dmp-5000_firmware:*:*:*:*:*:*:*:* |
| daktronics | dmp-8000_firmware |
< 8.117.0.0 >= 9.0.0.0, < 9.43.0.0 >= 10.0.0.0, < 10.34.0.0 cpe:2.3:o:daktronics:dmp-8000_firmware:*:*:*:*:*:*:*:* |
| daktronics | vfc-dmp-5000_firmware |
< 8.117.0.0 >= 9.0.0.0, < 9.43.0.0 >= 10.0.0.0, < 10.34.0.0 cpe:2.3:o:daktronics:vfc-dmp-5000_firmware:*:*:*:*:*:*:*:* |
Original title
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using t...
Original description
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.
nvd CVSS3.1
8.1
nvd CVSS4.0
9.3
Vulnerability type
CWE-798
Use of Hard-coded Credentials
Published: 26 Jun 2026 · Updated: 23 Jul 2026 · First seen: 26 Jun 2026