Daktronics Controller Flaws Let Hackers Hijack Highway Signs
Critical and high-severity vulnerabilities in Daktronics controllers could allow remote attackers to tamper with highway signs, electronic scoreboards, and digital billboards worldwide. According to a CISA advisory, three flaws affect the Daktronics VFC-DMP-5000, DMP-5000, and DMP-8000 controllers, which manage large-scale LED video displays deployed across sports arenas, international airports, and metropolitan roadways. The vulnerabilities include a pre-authentication path traversal bug that exposes arbitrary file system paths, an authenticated arbitrary file upload flaw, and default administrator credentials that grant full root-level system access. CISA warned that successful exploitation could give an unauthenticated attacker complete control over a display controller.
Princeton undergraduate researcher Thomas Jou, who reported the flaws through CISA's VINCE coordination platform in early January, told SecurityWeek that he identified multiple internet-exposed controllers during field testing, with the majority still running factory-default admin credentials. From there, an attacker could chain the file upload vulnerability to push malicious content or code onto the device. In practical terms, this could mean falsified roadway alerts, spoofed emergency messages on billboards, or full device compromise. "The devices also shipped with default administrator credentials that weren't required to be changed, and field testing showed a majority of internet-exposed units were still using them," Jou explained. Network administrators responsible for such infrastructure can audit their own exposure using a port scanner to identify controllers inadvertently accessible from the public internet.
Daktronics has released patched firmware versions and urged customers to change default passwords immediately. Operators should also verify that no factory credentials remain active by checking them against a password checker and ensure devices are segmented from public-facing networks. While the vendor responded swiftly to the coordinated disclosure, Jou noted that securing deployments ultimately falls on the customer, not the manufacturer. A broader privacy checkup of any environment hosting ICS hardware is a recommended first step toward reducing attack surface.