Impact
The vulnerability arises from the use of hardcoded MQTT credentials embedded in Bransys ELD firmware. These credentials allow any entity that can reach the MQTT broker to gain read access to real‑time data from every active device connected to the affected broker. The impact is a confidentiality breach of vehicle telemetry and location data, with potential broader privacy and operational consequences. The weakness maps to CWE‑798: Use of Hard‑coded Credentials.
Affected Systems
Bransys ELD firmware that contains hardcoded MQTT credentials is affected. Devices running older versions—any Android release before 11.00.00 and any iOS release before 1.1.54—remain vulnerable until patched.
Risk and Exploitability
The CVSS base score of 6.9 reflects a moderate severity; the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by accessing the MQTT broker network and using the embedded credentials, a scenario that is feasible if the broker is reachable over a network plane. Based on the description, it is inferred that an attacker who can reach the MQTT broker could use the hardcoded credentials to read data. While the CVSS does not indicate a remote code execution vector, the ability to read sensitive data is still significant.
OpenCVE Enrichment