Bransys ELD
September 17, 2026 · CISA (US-CERT) · Severity: CRITICAL
View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) iOS <1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) CVSS Vendor Equipment Vulnerabilities v3 7.5 Bransys Bransys ELD Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: United States Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-86520 The affected product is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker. View CVE Details Affected Products Bransys ELD Vendor:Bransys Product Version:Bransys Android: <11.00.00, Bransys iOS: <1.1.54 Product Status:known_affected Remediations Vendor fixBransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on version 1.1.54 or newer. Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-86689 The affected product is susceptible to cleartext transmission of sensitive information, which could allow an attacker to connect to the broker and read all data. View CVE Details Affected Products Bransys ELD Vendor:Bransys Product Version:Bransys Android: <11.00.00, Bransys iOS: <1.1.54 Product Status:known_affected Remediations Vendor fixBransys recommends that users update their system through the app store. Android users should be on version...
Key Takeaways
- Bransys ELD vulnerabilities could allow attackers to manipulate electronic logging device data used for commercial vehicle compliance monitoring and fleet management.
- ELD security flaws have real-world safety implications as manipulated logging data could conceal driver fatigue violations and compromise transportation regulatory compliance.
- Fleet operators using Bransys ELD devices should apply security updates and monitor for unauthorized modifications to driver logs and vehicle tracking data.