VYPR
patchPublished Aug 7, 2026· 1 source

Bendix Truck Brake Controller Recall Secretly Patched Critical Security Flaws

A safety recall for Bendix's EC80 heavy-truck brake controller, initially addressing memory corruption, has been found to secretly patch severe security vulnerabilities including remote code execution.

A safety recall initially issued in late 2024 for Bendix's EC80 heavy-truck brake controller has been revealed to have quietly patched a suite of critical security vulnerabilities, including a wirelessly reachable remote code execution flaw, alongside the publicly disclosed memory corruption issues. The findings were presented by Ben Gardiner, senior cybersecurity research engineer at the National Motor Freight Traffic Association (NMFTA), at the Black Hat USA 2026 conference.

The EC80 electronic control unit (ECU) is a vital component in heavy commercial vehicles, managing essential functions such as anti-lock braking, traction control, and stability. It communicates via the J2497 powerline databus, a standard used since 2001 for trailer ABS warning-light requirements.

Initially, three original equipment manufacturers (OEMs) recalled approximately 450,000 units due to memory corruption issues in the EC80, which Bendix attributed to line noise on the J2497 bus. Bendix released a firmware update to address these safety concerns.

However, Gardiner's in-depth reverse engineering of pre- and post-update firmware from affected EC80 units uncovered that the update removed dozens of functions. Within this deleted code, he identified several significant vulnerabilities. These included buffer-handling flaws capable of crashing the ECU and enabling remote code execution, a hardcoded password that could disable traction control, and another flaw that presented a theoretical pathway to both vehicle crashes and code execution.

The security implications are substantial because the J2497 bus can be accessed remotely, either through a previously disclosed NMFTA vulnerability or via a compromised trailer telematics device. NMFTA researchers demonstrated in a controlled environment and on a closed track that triggering these vulnerabilities could lead to a denial-of-service (DoS) state, causing a complete loss of CAN bus traffic. This DoS state consistently resulted in the loss of speedometer, steering assist, shifting, and ABS pulsing, requiring a battery disconnect for recovery.

While the direct risk of causing a crash is not clear-cut as driver control is not entirely removed, the potential for immobilizing a truck, perhaps for cargo theft, or causing significant disruption is considerable. NMFTA noted that the severity of these undisclosed vulnerabilities was sufficient for Bendix to include them in the recall, though the lack of CVE identifiers for these specific security flaws has drawn criticism for potentially obscuring their significance.

NMFTA proactively briefed Bendix, two affected OEMs, and regulatory bodies like NHTSA and Transport Canada before making their findings public. According to NHTSA's recall completion tracker, completion rates for this recall varied significantly, ranging from 0% to 99% as of mid-July, with NMFTA estimating typical industry-wide completion rates plateau around 80% due to various factors.

Following the Black Hat presentation, NMFTA published a comprehensive 179-page technical whitepaper detailing their extensive findings. Bendix has not yet responded to requests for comment regarding these newly revealed security vulnerabilities.

Synthesized by Vypr AI