← Terug naar overzicht

The Bendix EC80 Brake ECU is affected by a stack-based buffer overflow vulnerability tracked as CVE-2026-67560. An attacker can exploit this flaw by sending a crafted payload to crash the ECU or remotely execute arbitrary code. The vulnerability also allows injection of arbitrary CAN bus traffic, which can disrupt critical vehicle functions. Impacted systems may lose ABS braking, steering assist, speedometer readings, and transmission shifting capabilities. This represents a serious safety risk for vehicles relying on the Bendix EC80 for braking control. The vulnerability is documented in a CISA ICS advisory (ICSA-26-237-05) and the NVD. Exploitation could be performed remotely, raising concerns about transportation and fleet safety. No patch or mitigation details are included in the article, but CISA and CSAF files are referenced for further guidance.

Affected products

  • Bendix EC80 Brake ECU

Related CVE's

  • CVE-2026-67560

Categories

  • Critical Infrastructure
  • Mobile & IoT
  • Zero-Day Vulnerabilities