Bendix EC80 Brake ECU
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause the loss of ABS functions, steering assist, speedometer, shifting capabilities, or disable automatic traction control. The following versions of Bendix EC80 Brake ECU are affected: EC80ESP+ J1708 Z228999 EC80ESP+ 6S/6M Z228999 EC80ESP+ PLC Z228999 EC80ESP+ 2nd CAN Z228999 EC80ESP+ Integrated TPMS Z228999 EC80ESP 6S/6M Z266494 EC80ESP PLC Z266494 EC80ESP 2nd CAN Z266494 EC80ESP CAN Gateway Z266494 EC80ESP 4S/4M Z286098 EC80ESP PLC Z286098 CVSS Vendor Equipment Vulnerabilities v3 7.5 Bendix Bendix EC80 Brake ECU Stack-based Buffer Overflow, Out-of-bounds Write, Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: United States, Canada Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-67560 The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting. View CVE Details Affected Products Bendix EC80 Brake ECU Vendor: Bendix Product Version: Bendix EC80ESP+ J1708: Z228999, Bendix EC80ESP+ 6S/6M: Z228999, Bendix EC80ESP+ PLC: Z228999, Bendix EC80ESP+ 2nd CAN: Z228999, Bendix EC80ESP+ Integrated TPMS: Z228999, Bendix EC80ESP 6S/6M: Z266494, Bendix EC80ESP PLC: Z266494, Bendix EC80ESP 2nd CAN: Z266494, Bendix EC80ESP CAN Gateway: Z266494, Bendix EC80ESP 4S/4M: Z286098, Bendix EC80ESP PLC: Z286098 Product Status: known_affected Remediations Mitigation Bendix recommends users update their firmware to the most recent firmware version releases. Users that need more help should contact Bendix directly at info@Bendix.com. mailto:info@Bendix.com Vendor fix EC80ESP+ J1708: Z228999 users should update their firmware to version Z300822. Ve
CSIRTS triage
- What
- Bendix EC80 Brake ECU firmware contains stack-based buffer overflow and hard-coded credential vulnerabilities affecting brake and traction control systems.
- Who is affected
- Multiple Bendix EC80 ECU variants in heavy vehicles across North America.
- Urgency
- Critical; memory corruption in brake control firmware can disable ABS, steering assist, and traction control, creating severe vehicle safety hazards.
- Action
- Contact Bendix for firmware updates addressing stack overflow and credential hardening in EC80 variants.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Bendix EC80 Brake ECU
Get an email when a new Bendix EC80 Brake ECU advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-05
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-67560 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-68967 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71396 | coverage & exploitation status | NVD · CVE.org |
More from CISA Cybersecurity Advisories
- criticalA Tale of Two SOCs: Insights From Two Red Team Assessments2026-08-25
- criticalZoneminder2026-08-25
- criticalSiemens SIMATIC IoT2050 Advanced2026-08-25
- criticalFURUNO FA-50 Class B AIS Transponder2026-08-25
- criticalEbyte NE2-D112026-08-25