Bendix EC80 Brake ECU
MonitorCVSS 7.5ICS-CERT ICSA-26-237-05Aug 25, 2026
Manufacturing
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
The Bendix EC80 brake ECU contains buffer overflow and out-of-bounds write vulnerabilities (CWE-121, CWE-787) and hardcoded credentials (CWE-798) that could allow an attacker to disable critical safety functions. Exploitation could result in loss of ABS, steering assist, speedometer, shifting capabilities, or automatic traction control. Affected products include EC80ESP+ variants (J1708, 6S/6M, PLC, 2nd CAN, Integrated TPMS) and EC80ESP variants (6S/6M, PLC, 2nd CAN, CAN Gateway, 4S/4M).
What this means
What could happen
An attacker could disable critical safety functions in the vehicle braking system, including ABS, steering assist, traction control, and speedometer, creating immediate risk of loss of control and collision.
Who's at risk
Vehicle manufacturers and fleet operators using Bendix EC80 series electronic brake control units in commercial trucks and vehicles. This affects any fleet management or manufacturing operation that relies on these braking systems for safe vehicle operation.
How it could be exploited
An attacker with access to the vehicle's CAN bus or J1708 network could send crafted messages to the EC80 brake ECU to trigger buffer overflow or out-of-bounds write vulnerabilities, causing the system to execute arbitrary code that disables safety functions.
Prerequisites
- Network access to the vehicle's CAN bus or J1708 vehicle network
- Physical access to vehicle or ability to reach the in-vehicle network from an OBD-II port or similar diagnostic interface
- No authentication required to send commands to the ECU
affects safety systemslow complexity attackno authentication requiredremotely exploitable via vehicle network
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
EC80ESP+ J1708: Z228999Z228999Fix available
EC80ESP+ 6S/6M: Z228999Z228999Fix available
EC80ESP+ PLC: Z228999Z228999Fix available
EC80ESP+ 2nd CAN: Z228999Z228999Fix available
EC80ESP+ Integrated TPMS: Z228999Z228999Fix available
EC80ESP 6S/6M: Z266494Z266494Fix available
EC80ESP PLC: Z266494Z266494Fix available
EC80ESP 2nd CAN: Z266494Z266494Fix available
Remediation & Mitigation
0/6
Schedule — requires maintenance window
0/6Patching may require device reboot — plan for process interruption
HOTFIXUpdate EC80ESP+ J1708 (Z228999) firmware to version Z300822 or later
HOTFIXUpdate EC80ESP+ 6S/6M (Z228999) firmware to version Z300822 or later
HOTFIXUpdate EC80ESP+ PLC (Z228999) firmware to version Z300822 or later
HOTFIXUpdate EC80ESP+ 2nd CAN (Z228999) firmware to version Z300822 or later
HOTFIXUpdate EC80ESP+ Integrated TPMS (Z228999) firmware to version Z300822 or later
HOTFIXUpdate all EC80ESP variant firmware (Z266494 and Z286098 models) to latest vendor-released versions
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/91345961-f534-41c3-bb0f-8b1a195c25e5Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.