Three vulnerabilities in Daktronics controllers used in highway signs and digital billboards could give attackers full remote control, according to a CISA advisory published last week.
Daktronics makes large-scale LED displays and electronic scoreboards found everywhere from sports arenas to interstate highways. The affected controllers — VFC-DMP-5000, DMP-5000, and DMP-8000 — power those displays.
The flaws are serious. There’s a path traversal vulnerability that works without authentication, letting anyone enumerate files on the system. Then there’s an authenticated arbitrary file upload issue. And the devices shipped with default admin credentials that most users never changed.
In practical terms, an attacker could read files off the device, discover those default credentials, then push malicious content or code onto the system. Imagine a highway sign suddenly displaying fake alerts or malicious messages. That’s the realistic worst case.
Thomas Jou, an undergraduate at Princeton who discovered the flaws, found multiple internet-exposed controllers during field testing. He reported them through CISA’s VINCE platform in early January. Daktronics acknowledged the findings quickly and had patched firmware ready by early March.
“The remaining time before publication was largely coordinated advisory preparation and customer notification,” Jou told SecurityWeek. Daktronics has advised users to change default passwords and apply the patches.
Here’s the catch: it’s up to Daktronics customers, not the vendor, to make sure their installations aren’t exposed to the internet. If your billboard controller is online and still using default credentials, you should fix that today.
