Description
Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.
Published: 2026-09-18
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Read Access to Real‑Time Vehicle Data
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from the use of hardcoded MQTT credentials embedded in Bransys ELD firmware. These credentials allow any entity that can reach the MQTT broker to gain read access to real‑time data from every active device connected to the affected broker. The impact is a confidentiality breach of vehicle telemetry and location data, with potential broader privacy and operational consequences. The weakness maps to CWE‑798: Use of Hard‑coded Credentials.

Affected Systems

Bransys ELD firmware that contains hardcoded MQTT credentials is affected. Devices running older versions—any Android release before 11.00.00 and any iOS release before 1.1.54—remain vulnerable until patched.

Risk and Exploitability

The CVSS base score of 6.9 reflects a moderate severity; the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by accessing the MQTT broker network and using the embedded credentials, a scenario that is feasible if the broker is reachable over a network plane. Based on the description, it is inferred that an attacker who can reach the MQTT broker could use the hardcoded credentials to read data. While the CVSS does not indicate a remote code execution vector, the ability to read sensitive data is still significant.

Generated by OpenCVE AI on September 19, 2026 at 18:21 UTC.

Remediation

Vendor Solution

Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on version 1.1.54 or newer.


OpenCVE Recommended Actions

  • Update Bransys ELD to the latest version available through the app store (Android 11.00.00+ or iOS 1.1.54+).
  • If an immediate update is not possible, isolate the affected MQTT broker from external networks or block traffic on the broker's ports to prevent unauthorized credential usage.
  • Implement a monitoring solution that detects attempted MQTT connections using the known hardcoded credentials and alerts administrators.

Generated by OpenCVE AI on September 19, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Bransys
Bransys eld
Vendors & Products Bransys
Bransys eld

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.
Title Use of Hard-coded Credentials in Bransys ELD
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-18T16:21:12.462Z

Reserved: 2026-09-09T21:28:27.096Z

Link: CVE-2026-77960

cve-icon Vulnrichment

Updated: 2026-09-18T16:21:07.991Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:09.583

Modified: 2026-09-18T19:03:28.367

Link: CVE-2026-77960

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:29:03Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials