CISA warns Daktronics display controller flaws can let attackers remotely hijack highway signs and digital billboards

CISA warned that vulnerabilities in Daktronics display controllers could let attackers remotely tamper with highway signs, digital billboards, and other large electronic displays. The advisory covers Daktronics VFC-DMP-5000, DMP-5000, and DMP-8000 controllers and includes an unauthenticated path traversal flaw, an authenticated arbitrary file upload flaw, and default administrator credentials; together they can enable root-level control. Daktronics released patched firmware, and researchers found multiple internet-exposed controllers still reachable online.
Why it matters: Organizations using these controllers could have public-facing signs altered to show false or malicious messages, and exposed devices may be fully compromised. This is an urgent patch-and-hardening story for operators of transportation, advertising, venue, and airport display systems: update firmware, remove internet exposure, and change default passwords immediately.

Sources

New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking
Eduard Kovacs 2026.06.30 100% relevant
This article appears to be the first concrete report tying CISA's advisory and Daktronics' patches to remotely exploitable controller flaws affecting highway signs, billboards, and other large public display systems.
← Back to all stories