CVE-2026-28701
Received Received - Intake
Directory Traversal in Daktronics Controller Firmware

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: ICS-CERT

Description
Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-27
AI Q&A
2026-06-27
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability affects various versions of Daktronics Controller Firmware and allows both authenticated and unauthenticated remote users to escape the intended directory restrictions and enumerate arbitrary file system paths.

Impact Analysis

The vulnerability can have a severe impact as it allows remote attackers to access and enumerate arbitrary file system paths without proper authorization. This can lead to unauthorized disclosure of sensitive information, potential system compromise, and disruption of confidentiality, integrity, and availability.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-28701. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart