{"id":81143,"date":"2026-06-27T02:18:56","date_gmt":"2026-06-26T22:48:56","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2026-33560-daktronics-controller-firmware-unrestricted-upload-of-file-with-dangerous-type\/"},"modified":"2026-06-27T02:18:56","modified_gmt":"2026-06-26T22:48:56","slug":"cve-2026-33560-daktronics-controller-firmware-unrestricted-upload-of-file-with-dangerous-type","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2026-33560-daktronics-controller-firmware-unrestricted-upload-of-file-with-dangerous-type\/","title":{"rendered":"CVE-2026-33560 &#8211; Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type"},"content":{"rendered":"<p>CVE ID :CVE-2026-33560<\/p>\n<p>  Published : June 26, 2026, 10:48 p.m. | 56\u00a0minutes ago<\/p>\n<p>  Description :The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.<\/p>\n<p>  Severity: 8.4 | HIGH<\/p>\n<p>  Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID :CVE-2026-33560 Published : June 26, 2026, 10:48 p.m. | 56\u00a0minutes ago Description :The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-81143","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/81143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=81143"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/81143\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=81143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=81143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=81143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}