CISA Flags Multiple Vulnerabilities in Bransys ELD Software
CISA has identified several critical vulnerabilities in Bransys ELD applications for both Android and iOS, potentially exposing sensitive telemetry data and firmware.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding multiple vulnerabilities discovered in Bransys ELD software, affecting versions prior to Android 11.00.00 and iOS 1.1.54. These flaws, if exploited, could grant unauthorized access to critical telemetry data and device firmware, posing a significant risk to users in the transportation sector.
The vulnerabilities stem from several security weaknesses, including the use of hard-coded credentials and the cleartext transmission of sensitive information. Specifically, CVE-2026-86520 involves hard-coded MQTT credentials, which could allow an attacker to gain read access to real-time data from any active device connected to the affected MQTT broker. This could provide a broad overview of operational data across a fleet.
Another critical vulnerability, CVE-2026-77960, also exploits hard-coded credentials, this time for FTP. This flaw could enable an attacker to connect to the FTP server and exfiltrate sensitive data. The presence of hard-coded credentials in both MQTT and FTP protocols indicates a fundamental security oversight in the software's design, making it susceptible to credential stuffing or simple brute-force attacks if the credentials are not changed.
Furthermore, CVE-2026-86689 addresses the cleartext transmission of sensitive information. This vulnerability allows attackers to intercept and read data transmitted over the network without encryption. This could expose a wide range of sensitive details, including user credentials, operational parameters, and other proprietary information, depending on what data the ELD system transmits.
The potential impact of these vulnerabilities is significant. Unauthorized access to telemetry data could reveal operational patterns, driver behavior, and vehicle diagnostics. More critically, unauthorized access to firmware could allow attackers to tamper with device functionality, disable safety features, or even install malicious code, potentially leading to widespread disruption in transportation logistics.
Bransys has acknowledged these issues and recommends that users update their Bransys ELD applications to the latest versions available through their respective app stores. Android users should ensure they are running version 11.00.00 or newer, while iOS users should update to version 1.1.54 or later. These updates are crucial for patching the identified vulnerabilities and protecting against potential exploitation.
CISA advises organizations to implement defensive measures to mitigate the risks associated with these vulnerabilities. These include minimizing network exposure for control system devices, ensuring they are not accessible from the internet, and segmenting control system networks behind firewalls. When remote access is necessary, secure methods like VPNs should be employed, and all VPN software should be kept up-to-date.
While no known public exploitation targeting these specific vulnerabilities has been reported to CISA at this time, the nature of the flaws—particularly hard-coded credentials and cleartext transmission—makes them attractive targets for opportunistic attackers. The transportation sector, which relies heavily on ELD systems for compliance and operational efficiency, is urged to prioritize these updates.