ZeroHour

CVE-2026-86689

CVSS
EPSS
Published
Modified

In the news

Bransys ELD

CISA reports Bransys ELD apps ship hardcoded MQTT and FTP credentials plus cleartext transport, exposing real-time telemetry for connected fleet devices.

CISA's advisory covers three Bransys ELD mobile app flaws: CVE-2026-86520 hardcoded MQTT credentials (CVSS 7.5), CVE-2026-86689 cleartext transmission of sensitive information, and CVE-2026-77960 hardcoded FTP credentials. Exploitation could allow unauthorized reading of real-time telemetry data from every active device connected to affected brokers across a subset of carriers. Android versions below 11.00.00 and iOS versions below 1.1.54 are affected; no public exploitation has been reported to CISA.