Executive brief
Bendix EC80 Brake ECU is a brake control module used in heavy-duty commercial vehicles to manage anti-lock braking (ABS) and related safety functions. A stack-based buffer overflow vulnerability allows an attacker to crash the ECU or remotely execute code via CAN bus traffic, potentially disabling critical safety systems including ABS, steering assist, and speedometer—creating a severe risk to vehicle safety and occupant protection.
Technical details
The vulnerability is a stack-based buffer overflow (CWE-121) in the Bendix EC80 Brake ECU firmware. An attacker with adjacent network access (CAN bus proximity) can send a crafted payload to trigger the overflow, enabling arbitrary code execution or CAN bus traffic injection without authentication. The attack vector is adjacent network (CAN bus), and no special preconditions or user interaction is required. Successful exploitation results in loss of critical vehicle safety functions (ABS, steering assist, speedometer, shifting) and potential arbitrary ECU control. Patches are available: firmware version Z300822 for Z228999 variants, Z302578 for Z266494 variants, and Z302579 for Z286098 variants.
Affected products
- Bendix EC80 Brake ECU EC80ESP+ J1708 Z228999, EC80ESP+ 6S/6M Z228999, EC80ESP+ PLC Z228999, EC80ESP+ 2nd CAN Z228999, EC80ESP+ Integrated TPMS Z228999, EC80ESP 6S/6M Z266494, EC80ESP PLC Z266494, EC80ESP 2nd CAN Z266494, EC80ESP CAN Gateway Z266494, EC80ESP 4S/4M Z286098, EC80ESP PLC Z286098
Timeline
- 2026-08-25: disclosed
- 2026-08-28: advisory: CISA ICSA-26-237-05 published
- 2026-08-25: patched: Firmware patches available: Z300822, Z302578, Z302579 depending on variant