CVE-2026-86520: Use of Hard-coded Credentials in Bransys ELD
Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.00.00 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.1.54
Event History
Frequently Asked Questions
Is exposure limited to one carrier or fleet using the product?
No. The hardcoded MQTT credentials can provide access to real-time data for every active device among the subset of carriers connected to the affected MQTT broker.
What access does successful exploitation provide?
The credentials grant read access to real-time device data. The supplied information does not indicate write access, data modification, or service disruption capability.