CVE-2026-67560
7.5
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Bendix | EC80ESP+ J1708 | Z228999 | affected |
| Bendix | EC80ESP+ J1708 | Z300822 | unaffected |
| Bendix | EC80ESP+ 6S/6M | Z228999 | affected |
| Bendix | EC80ESP+ 6S/6M | Z300822 | unaffected |
| Bendix | EC80ESP+ PLC | Z228999 | affected |
| Bendix | EC80ESP+ PLC | Z300822 | unaffected |
| Bendix | EC80ESP+ 2nd CAN | Z228999 | affected |
| Bendix | EC80ESP+ 2nd CAN | Z300822 | unaffected |
| Bendix | EC80ESP+ Integrated TPMS | Z228999 | affected |
| Bendix | EC80ESP+ Integrated TPMS | Z300822 | unaffected |
| Bendix | EC80ESP 6S/6M | Z266494 | affected |
| Bendix | EC80ESP 6S/6M | Z302578 | unaffected |
| Bendix | EC80ESP PLC | Z266494 | affected |
| Bendix | EC80ESP PLC | Z302578 | unaffected |
| Bendix | EC80ESP 2nd CAN | Z266494 | affected |
| Bendix | EC80ESP 2nd CAN | Z302578 | unaffected |
| Bendix | EC80ESP CAN Gateway | Z266494 | affected |
| Bendix | EC80ESP CAN Gateway | Z302578 | unaffected |
| Bendix | EC80ESP 4S/4M | Z286098 | affected |
| Bendix | EC80ESP 4S/4M | Z302579 | unaffected |
| Bendix | EC80ESP PLC | Z286098 | affected |
| Bendix | EC80ESP PLC | Z302579 | unaffected |
Weaknesses
- CWE-121: CWE-121
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-05
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-05.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.