Impact
Bransys ELD ships with hardcoded MQTT credentials in cleartext, which allows any party that can reach the MQTT broker to obtain read access to real‑time data from every active device. This flaw constitutes a significant confidentiality breach, allowing exposure of sensitive vehicle information without authentication, and corresponds to CWE-319.
Affected Systems
The vulnerability affects Bransys ELD applications on both Android and iOS. Android users should update to version 11.00.00 or newer, and iOS users should update to version 1.1.54 or newer via the app store.
Risk and Exploitability
The CVSS score of 8.2 signals a high severity risk, and its EPSS score is 0.0015 (<1%) while the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. Based on the description, an attacker who can connect to the affected MQTT broker can simply use the embedded credentials to read all live data from every device. The prerequisite for exploitation is access to the broker; no additional software or privileged access is required, and the attack vector is therefore an untrusted MQTT connection with exposed credentials.
OpenCVE Enrichment