Impact
Bransys ELD is shipped with hard‑coded MQTT credentials that give read‑only access to real‑time device data across a subset of carriers. Because these credentials are embedded in the firmware, any entity that discovers or guesses them can connect to the broker and retrieve sensitive information without authentication, violating confidentiality.
Affected Systems
Vendors affected include Bransys ELD for both Android and iOS platforms. The fix is to update Android devices to version 11.00.00 or later and iOS devices to version 1.1.54 or newer via the official app store.
Risk and Exploitability
The CVSS score of 8.7 confirms high severity for unauthorized data access. The EPSS score of less than 1% indicates that the likelihood of exploitation in the near term is very small but not zero. The vulnerability is not listed in CISA's KEV catalog. Exploitation would involve an attacker connecting to the MQTT broker using the embedded static credentials, which does not require privileged network access beyond the ability to reach the broker; the attack is remote and could be performed from any network that can see the broker. While the probability is low, the impact remains significant due to potential exposure of real‑time device data.
OpenCVE Enrichment