Description
Bendix EC80 Brake ECU
is vulnerable to a stack-based buffer overflow, which may allow an
attacker to crash the ECU. A crafted payload can then be used to
remotely execute arbitrary code or inject arbitrary CAN bus traffic.
This could cause the loss of the ABS function, steering assist,
speedometer, and shifting.
Published: 2026-08-27
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com. * EC80ESP+ J1708: Users should update their firmware to version Z300822. * EC80ESP+ 6S/6M: Users  should update their firmware to version Z300822. * EC80ESP+ PLC: Users  should update their firmware to version Z300822. * EC80ESP+ 2nd CAN: Users should update their firmware to version Z300822. * EC80ESP+ Integrated TPMS: Users should update their firmware to version Z300822. * EC80ESP 6S/6M: Users should update their firmware to version Z302578. * EC80ESP PLC: Users should update their firmware to version Z302578. * EC80ESP 2nd CAN: Users should update their firmware to version Z302578. * EC80ESP CAN Gateway: Users should update their firmware to version Z302578. * EC80ESP 4S/4M: Users should update their firmware to version Z302579. * EC80ESP PLC: Users should update their firmware to version Z302579.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.
Title Stack-based Buffer Overflow in Bendix EC80 Brake ECU
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-27T20:54:20.022Z

Reserved: 2026-08-10T16:03:40.493Z

Link: CVE-2026-67560

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T00:18:08.150

Modified: 2026-08-28T00:18:08.150

Link: CVE-2026-67560

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow