ELD
by Bransys
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-86520 | hig | 0.49 | 7.5 | — | Sep 17, 2026 | The affected product is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker. | ||
| CVE-2026-86689 | med | 0.38 | 5.9 | — | Sep 17, 2026 | The affected product is susceptible to cleartext transmission of sensitive information, which could allow an attacker to connect to the broker and read all data. | ||
| CVE-2026-77960 | med | 0.34 | 5.3 | — | Sep 17, 2026 | The affected product ships with hardcoded FTP credentials which could allow an attacker to connect to the server and read data. |
- risk 0.49cvss 7.5epss —
The affected product is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.
- risk 0.38cvss 5.9epss —
The affected product is susceptible to cleartext transmission of sensitive information, which could allow an attacker to connect to the broker and read all data.
- risk 0.34cvss 5.3epss —
The affected product ships with hardcoded FTP credentials which could allow an attacker to connect to the server and read data.