CVE-2026-77960: Use of Hard-coded Credentials in Bransys ELD
Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bransys ELD (Android)to a version that resolves this vulnerability.Fixed in 11.00.00 - Upgrade
Upgrade
Bransys ELD (iOS)to a version that resolves this vulnerability.Fixed in 1.1.54 - Compensating control
Because Bransys ELD ships with hardcoded MQTT credentials that grant read access to real-time data for every active device across a subset of carriers connected to the affected MQTT broker, restrict/limit exposure of that MQTT broker and its credentials (e.g., through network access controls so only authorized systems/users can reach the broker).
Event History
Frequently Asked Questions
What access would an unauthenticated attacker gain?
The hardcoded MQTT credentials grant read access to real-time data for every active device across a subset of carriers connected to the affected MQTT broker. The available information indicates confidentiality impact only, with no stated ability to alter data or disrupt service.
Which deployments are exposed?
Exposure applies to Bransys ELD devices connected to the affected MQTT broker, specifically across a subset of carriers. The provided information does not identify the affected carriers, broker address, or software versions.
Does exploitation require an existing account or user interaction?
No. The supplied severity vector indicates network access, low attack complexity, no privileges required, and no user interaction.