Junglewise Threat Intelligence

CVE-2026-77960: Bransys ELD hardcoded FTP credentials

CVE-2026-77960 · Severity: medium · CVSS 5.3 · Published 2026-09-18

Executive brief

Bransys ELD is a mobile application used by vehicle operators to track electronic logging device data. The app ships with hardcoded FTP credentials embedded in the software, allowing attackers to connect to backend servers without authentication and read sensitive telemetry and device data. An attacker with network access to the FTP server could retrieve driver location, vehicle status, and other operational information affecting multiple carriers.

Technical details

CVE-2026-77960 involves hardcoded FTP credentials (CWE-798) in Bransys ELD that enable unauthenticated network access to data servers. The vulnerability affects Android versions before 11.00.00 and iOS versions before 1.1.54. An attacker can leverage these static credentials to enumerate and exfiltrate telemetry data; vendor patches are available via app store updates.

Affected products

  • Bransys ELD Android < 11.00.00, iOS < 1.1.54

Timeline

  • 2026-09-17: disclosed

References

Related threats