ZeroHour

CVE-2026-67560

mass

Stack-based buffer overflow in Bendix EC80 Brake ECU enables RCE and CAN bus injection

CVSS 4.0
7.7 high
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-67560 is a stack-based buffer overflow (CWE-121) in the Bendix EC80 Brake ECU, an electronic control unit used in commercial vehicle braking systems. An attacker with access to the vehicle's adjacent network (the vehicle CAN bus) can send a crafted payload that, despite high attack complexity, crashes the ECU and can then be extended to execute arbitrary code or inject arbitrary CAN bus traffic. Successful exploitation could disable safety-relevant functions including ABS braking, steering assist, the speedometer, and shifting. Operators of commercial tractors and trailers fitted with Bendix EC80 units are potentially affected. No public proof-of-concept, known in-the-wild exploitation, or KEV listing exists; EPSS assigns a low 0.3% probability of exploitation within 30 days.

What to do: Identify which fleet vehicles (tractors and trailers) are fitted with Bendix EC80 ECUs and check the CISA ICS-CERT/Bendix advisory for fixed firmware, applying updates through authorized Bendix service channels. Until updated, limit access to the vehicle CAN bus from untrusted or aftermarket devices (telematics units, diagnostic adapters) and investigate unexpected ABS, steering-assist, or speedometer faults promptly. No exploitation is currently known, so routine CAN traffic monitoring is a reasonable precaution rather than an urgent action.

Affected
Bendix EC80 Brake ECU
Estimated exposure
masslikely millions of EC80 units installed across North American commercial tractors and trailers — Bendix is one of the largest suppliers of ABS/ESC brake ECUs for the North American heavy-truck and trailer market and the EC80 line has shipped in high volumes over many years, making a multi-million installed base plausible, though only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.

Weakness
CWE-121
Vector
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.