Description
Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.
Published: 2026-08-27
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a hard‑coded credential flaw in the Bendix EC80 Brake ECU that permits unauthorized authentication to the unit, enabling an attacker to disable automatic traction control. This disruption of a safety‑related function can reduce vehicle stability and increase the risk of an accident, representing a denial of critical vehicle controls. The weakness is identified as CWE‑798.

Affected Systems

Affected products include the Bendix EC80ESP 2nd CAN, 4S/4M, 6S/6M, CAN Gateway, PLC, and the EC80ESP+ variants (2nd CAN, 6S/6M, Integrated TPMS, J1708, PLC). Firmware updates required are Z302579 for the 4S/4M model, Z302578 for the 2nd CAN, 6S/6M, CAN Gateway and PLC units, and Z300822 for the EC80ESP+ family.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity vulnerability. The EPSS score is not available, so the current exploit probability is uncertain, and the vulnerability is not listed in the CISA KEV catalog. The attack vector likely requires access to the vehicle’s internal CAN or J1708 bus, either through physical penetration or a compromised on‑board system, to leverage the hard‑coded credentials and disable traction control. Given the danger to vehicle safety, the risk remains significant for environments where such access could be achieved.

Generated by OpenCVE AI on August 28, 2026 at 07:12 UTC.

Remediation

Vendor Solution

Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com. * EC80ESP+ J1708: Users should update their firmware to version Z300822. * EC80ESP+ 6S/6M: Users  should update their firmware to version Z300822. * EC80ESP+ PLC: Users  should update their firmware to version Z300822. * EC80ESP+ 2nd CAN: Users should update their firmware to version Z300822. * EC80ESP+ Integrated TPMS: Users should update their firmware to version Z300822. * EC80ESP 6S/6M: Users should update their firmware to version Z302578. * EC80ESP PLC: Users should update their firmware to version Z302578. * EC80ESP 2nd CAN: Users should update their firmware to version Z302578. * EC80ESP CAN Gateway: Users should update their firmware to version Z302578. * EC80ESP 4S/4M: Users should update their firmware to version Z302579. * EC80ESP PLC: Users should update their firmware to version Z302579.


OpenCVE Recommended Actions

  • Apply the manufacturer‑recommended firmware update for each impacted product (Z302579 for the EC80ESP 4S/4M, Z302578 for the EC80ESP 2nd CAN, 6S/6M, CAN Gateway, and PLC units, and Z300822 for all EC80ESP+ variants).
  • Limit access to the EC80ECU on the vehicle’s CAN or J1708 network by using network segmentation, firewall rules, or other physical controls to restrict unauthorized authentication attempts until the patch is applied.
  • If an immediate firmware update is not possible, consider disabling automatic traction control through the vehicle’s configuration, and inform users of the temporary safety risk. Contact Bendix support for detailed guidance if needed.

Generated by OpenCVE AI on August 28, 2026 at 07:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Bendix
Bendix ec80esp+ 2nd Can
Bendix ec80esp+ 6s/6m
Bendix ec80esp+ Integrated Tpms
Bendix ec80esp+ J1708
Bendix ec80esp+ Plc
Bendix ec80esp 2nd Can
Bendix ec80esp 4s/4m
Bendix ec80esp 6s/6m
Bendix ec80esp Can Gateway
Bendix ec80esp Plc
Vendors & Products Bendix
Bendix ec80esp+ 2nd Can
Bendix ec80esp+ 6s/6m
Bendix ec80esp+ Integrated Tpms
Bendix ec80esp+ J1708
Bendix ec80esp+ Plc
Bendix ec80esp 2nd Can
Bendix ec80esp 4s/4m
Bendix ec80esp 6s/6m
Bendix ec80esp Can Gateway
Bendix ec80esp Plc

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.
Title Use of Hard-coded Credentials in Bendix EC80 Brake ECU
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Bendix Ec80esp+ 2nd Can Ec80esp+ 6s/6m Ec80esp+ Integrated Tpms Ec80esp+ J1708 Ec80esp+ Plc Ec80esp 2nd Can Ec80esp 4s/4m Ec80esp 6s/6m Ec80esp Can Gateway Ec80esp Plc
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-27T20:45:52.804Z

Reserved: 2026-08-10T16:03:40.501Z

Link: CVE-2026-71396

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T00:18:10.313

Modified: 2026-08-28T00:18:10.313

Link: CVE-2026-71396

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T16:13:51Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials