EC80 Brake ECU
by Bendix
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-67560 | hig | 0.49 | 7.5 | — | Aug 25, 2026 | The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering… | ||
| CVE-2026-68967 | med | 0.42 | 6.5 | — | Aug 25, 2026 | The affected product is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write primitive, which could crash the ECU. | ||
| CVE-2026-71396 | med | 0.35 | 5.4 | — | Aug 25, 2026 | The affected product uses hard-coded credentials, which could allow an attacker to disable automatic traction control. |
- risk 0.49cvss 7.5epss —
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering…
- risk 0.42cvss 6.5epss —
The affected product is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write primitive, which could crash the ECU.
- risk 0.35cvss 5.4epss —
The affected product uses hard-coded credentials, which could allow an attacker to disable automatic traction control.