CVE-2026-71396: Use of Hard-coded Credentials in Bendix EC80 Brake ECU
Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bendix EC80 Brake ECU (EC80 series)to a version that resolves this vulnerability.Fixed in Z300822 - Upgrade
Upgrade
Bendix EC80 Brake ECU (EC80 series)to a version that resolves this vulnerability.Fixed in Z302578 - Upgrade
Upgrade
Bendix EC80 Brake ECU (EC80 series)to a version that resolves this vulnerability.Fixed in Z302579
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The supplied vector indicates adjacent-network access is required, with no privileges or user interaction needed. This suggests exposure is limited to attackers able to reach the ECU through an adjacent network path.
What security impact is identified?
Successful exploitation could allow an attacker to disable automatic traction control. The reported vector rates integrity and availability impact as low, with no confidentiality impact.