Bendix has an update available to handle stack-based buffer overflow, out-of-bounds write, and use of hard-coded credentials vulnerabilities in its EC80 Brake ECU, according to a report with CISA.

Successful exploitation of these vulnerabilities, discovered by Ben Gardiner of NMFTA, could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control.

Bendix EC80 Brake ECU is an advanced electronic control unit made by Bendix Commercial Vehicle Systems to manage and optimize air-braked heavy-duty commercial vehicles.

The following versions of Bendix EC80 Brake ECU suffer from the vulnerabilities:

  • EC80ESP+ J1708 Z228999
  • EC80ESP+ 6S/6M Z228999
  • EC80ESP+ PLC Z228999
  • EC80ESP+ 2nd CAN Z228999
  • EC80ESP+ Integrated TPMS Z228999
  • EC80ESP 6S/6M Z266494
  • EC80ESP PLC Z266494
  • EC80ESP 2nd CAN Z266494
  • EC80ESP CAN Gateway Z266494
  • EC80ESP 4S/4M Z286098
  • EC80ESP PLC Z286098
Vulnerabilities

In one issue, the affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then end up used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.

Schneider Bold

CVE-2026-67560 is the case number for the vulnerability, which has a CVSS V3 base score of 7.5. There is also a V4 base score of 7.7.

Additionally, the affected product is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write primitive, which could crash the ECU.

CVE-2026-68967 is the case number for the vulnerability, which has a CVSS V3 base score of 6.5. There is also a V4 base score of 7.1.

Also, the affected product uses hard-coded credentials, which could allow an attacker to disable automatic traction control.

CVE-2026-71396 is the case number for the vulnerability, which has a CVSS V3 base score of 5.4. There is also a V4 base score of 5.3.

The product sees use mainly in the transportation systems sector. The product sees action mostly in the United States and Canada.

No exploit currently targets this vulnerability.

Mitigations

In terms of mitigations, Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com.

The following are updated firmware offerings:

  • EC80ESP+ J1708: Z228999 users should update their firmware to version Z300822.
  • EC80ESP+ 6S/6M: Z228999 users should update their firmware to version Z300822.
  • EC80ESP+ PLC: Z228999 users should update their firmware to version Z300822.
  • EC80ESP+ 2nd CAN: Z228999 users should update their firmware to version Z300822.
  • EC80ESP+ Integrated TPMS: Z228999 users should update their firmware to version Z300822.
  • EC80ESP 6S/6M: Z266494 users should update their firmware to version Z302578.
  • EC80ESP PLC: Z266494 users should update their firmware to version Z302578.
  • EC80ESP 2nd CAN: Z266494 users should update their firmware to version Z302578.
  • EC80ESP CAN Gateway: Z266494 users should update their firmware to version Z302578.
  • EC80ESP 4S/4M: Z286098 users should update their firmware to version Z302579.
  • EC80ESP PLC: Z286098 users should update their firmware to version Z302579.

For additional information, click here for customer service.

ISSSource

Pin It on Pinterest

Share This