CISA Flags Three Daktronics Controller Flaws That Could Let Attackers Hijack Highway Signs

A researcher found the vulnerabilities in controllers widely used to drive digital billboards and roadway message signs. Exploitation could mean someone else controls what drivers read.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 2 min read
CISA Flags Three Daktronics Controller Flaws That Could Let Attackers Hijack Highway Signs
Share

Key points

  • CISA published an advisory covering three vulnerabilities in Daktronics controllers used in digital highway signs and large-format billboards.
  • A single researcher discovered all three flaws.
  • All three can be exploited remotely, with no physical access required.
  • No full technical details have been released publicly, consistent with staged patch rollout.
  • Affected operators should verify firmware versions, apply patches, and isolate controllers from internet-facing segments.

CISA has published an advisory covering three vulnerabilities in Daktronics controllers, the hardware behind a large share of North America's digital highway signs and commercial billboards. One researcher found all three. CISA's ICS advisory program covers operational technology and embedded controllers that rarely see the patch cadence of enterprise software.

Daktronics equipment runs message displays across highway corridors and sports venues. Arbitrary control of a roadway sign isn't a nuisance scenario; it's a public-safety one. Remote exploitation, confirmed by CISA, sharpens that concern: no physical access needed.

The agency hasn't published full technical specifics, which is standard practice when patches are still rolling out. Worth understanding what that silence doesn't mean: it doesn't mean the flaws are minor. CISA coordinates disclosure with vendors before going public, so this advisory being live means Daktronics had its window.

Two risks sit here, not one. The obvious: message manipulation visible to drivers. The less-discussed: a compromised display controller can become a foothold into adjacent network segments where transportation or venue management systems share infrastructure. We covered a structurally similar problem with internet-facing fuel tank gauges on 5 June, where the same pattern held: legacy operational hardware, remote exposure, no clear patch owner.

Daktronics had not posted a standalone security bulletin on its own site at time of publication. That gap matters. Operators relying on vendor comms alone may not know they're exposed.

Should you worry?

If your organisation runs Daktronics controllers, yes. This is a prioritisation call, not a patch-when-convenient item.

Check your firmware version against the affected range in CISA's ICS advisory. Apply vendor-issued patches immediately. Where patches aren't yet available, isolate controllers behind a firewall, remove them from internet-facing segments, and use a fully patched VPN for any remote management. Audit which network segments share connectivity with display controllers, log all access attempts, and report anomalous behaviour to CISA.

The thing worth watching: whether Daktronics publishes its own bulletin, and how long that takes. Vendor silence after a federal advisory is itself a signal.

© 2026 Threat Vectr