本文へスキップ
CodeAuditAgent

CVE-2026-33560

The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.

脆弱性の種類

The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.

影響を受ける製品

  • daktronics dmp-5000_firmware
  • daktronics dmp-5000
  • daktronics dmp-8000_firmware
  • daktronics dmp-8000
  • daktronics vfc-dmp-5000_firmware
  • daktronics vfc-dmp-5000

参考情報

攻撃者より先に脆弱性を見つけましょう。

GitHubでサインインすれば、1分以内に最初の監査を実行できます。無料プランはクレジットカード不要です。