Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com. * EC80ESP+ J1708: Users should update their firmware to version Z300822. * EC80ESP+ 6S/6M: Users should update their firmware to version Z300822. * EC80ESP+ PLC: Users should update their firmware to version Z300822. * EC80ESP+ 2nd CAN: Users should update their firmware to version Z300822. * EC80ESP+ Integrated TPMS: Users should update their firmware to version Z300822. * EC80ESP 6S/6M: Users should update their firmware to version Z302578. * EC80ESP PLC: Users should update their firmware to version Z302578. * EC80ESP 2nd CAN: Users should update their firmware to version Z302578. * EC80ESP CAN Gateway: Users should update their firmware to version Z302578. * EC80ESP 4S/4M: Users should update their firmware to version Z302579. * EC80ESP PLC: Users should update their firmware to version Z302579.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control. | |
| Title | Use of Hard-coded Credentials in Bendix EC80 Brake ECU | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-27T20:45:52.804Z
Reserved: 2026-08-10T16:03:40.501Z
Link: CVE-2026-71396
No data.
Status : Received
Published: 2026-08-28T00:18:10.313
Modified: 2026-08-28T00:18:10.313
Link: CVE-2026-71396
No data.
OpenCVE Enrichment
No data.
-
CWE-798
Use of Hard-coded Credentials