Executive brief
The Bendix EC80 Brake ECU is a critical safety controller in commercial vehicles that manages automatic traction control, ABS, steering assist, and other brake functions. An attacker with access to hard-coded credentials could remotely disable traction control and other safety systems, creating a serious risk of vehicle accidents and injuries.
Technical details
The Bendix EC80 Brake ECU contains hard-coded credentials that provide unauthenticated access to critical functionality. An attacker with network or physical access to the vehicle's CAN bus or diagnostic interface can use these credentials to authenticate and execute commands that disable automatic traction control and other safety-critical systems. The vulnerability requires adjacency to the vehicle (CAN bus or OBD-II access) but does not require user interaction. Exploitation could cause loss of ABS function, steering assist, speedometer, or shifting capabilities. Firmware updates addressing this and related vulnerabilities (CVE-2026-67560 and CVE-2026-68967) are available from Bendix.
Affected products
- Bendix EC80 Brake ECU EC80ESP+ J1708 Z228999, EC80ESP+ 6S/6M Z228999, EC80ESP+ PLC Z228999, EC80ESP+ 2nd CAN Z228999, EC80ESP+ Integrated TPMS Z228999, EC80ESP 6S/6M Z266494, EC80ESP PLC Z266494, EC80ESP 2nd CAN Z266494, EC80ESP CAN Gateway Z266494, EC80ESP 4S/4M Z286098, EC80ESP PLC Z286098
Timeline
- 2026-08-25: disclosed
- 2026-08-28: published