Description
Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.
Published: 2026-08-27
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com. * EC80ESP+ J1708: Users should update their firmware to version Z300822. * EC80ESP+ 6S/6M: Users  should update their firmware to version Z300822. * EC80ESP+ PLC: Users  should update their firmware to version Z300822. * EC80ESP+ 2nd CAN: Users should update their firmware to version Z300822. * EC80ESP+ Integrated TPMS: Users should update their firmware to version Z300822. * EC80ESP 6S/6M: Users should update their firmware to version Z302578. * EC80ESP PLC: Users should update their firmware to version Z302578. * EC80ESP 2nd CAN: Users should update their firmware to version Z302578. * EC80ESP CAN Gateway: Users should update their firmware to version Z302578. * EC80ESP 4S/4M: Users should update their firmware to version Z302579. * EC80ESP PLC: Users should update their firmware to version Z302579.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Bendix
Bendix ec80esp+ 2nd Can
Bendix ec80esp+ 6s/6m
Bendix ec80esp+ Integrated Tpms
Bendix ec80esp+ J1708
Bendix ec80esp+ Plc
Bendix ec80esp 2nd Can
Bendix ec80esp 4s/4m
Bendix ec80esp 6s/6m
Bendix ec80esp Can Gateway
Bendix ec80esp Plc
Vendors & Products Bendix
Bendix ec80esp+ 2nd Can
Bendix ec80esp+ 6s/6m
Bendix ec80esp+ Integrated Tpms
Bendix ec80esp+ J1708
Bendix ec80esp+ Plc
Bendix ec80esp 2nd Can
Bendix ec80esp 4s/4m
Bendix ec80esp 6s/6m
Bendix ec80esp Can Gateway
Bendix ec80esp Plc

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.
Title Use of Hard-coded Credentials in Bendix EC80 Brake ECU
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Bendix Ec80esp+ 2nd Can Ec80esp+ 6s/6m Ec80esp+ Integrated Tpms Ec80esp+ J1708 Ec80esp+ Plc Ec80esp 2nd Can Ec80esp 4s/4m Ec80esp 6s/6m Ec80esp Can Gateway Ec80esp Plc
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-28T15:57:46.738Z

Reserved: 2026-08-10T16:03:40.501Z

Link: CVE-2026-71396

cve-icon Vulnrichment

Updated: 2026-08-28T15:49:04.603Z

cve-icon NVD

Status : Received

Published: 2026-08-28T00:18:10.313

Modified: 2026-08-28T20:19:44.393

Link: CVE-2026-71396

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T16:13:51Z

Weaknesses