CVE-2026-67560

Summary

Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.

Affected Software

VendorProductVersion RangeStatus
BendixEC80ESP+ J1708Z228999affected
BendixEC80ESP+ J1708Z300822unaffected
BendixEC80ESP+ 6S/6MZ228999affected
BendixEC80ESP+ 6S/6MZ300822unaffected
BendixEC80ESP+ PLCZ228999affected
BendixEC80ESP+ PLCZ300822unaffected
BendixEC80ESP+ 2nd CANZ228999affected
BendixEC80ESP+ 2nd CANZ300822unaffected
BendixEC80ESP+ Integrated TPMSZ228999affected
BendixEC80ESP+ Integrated TPMSZ300822unaffected
BendixEC80ESP 6S/6MZ266494affected
BendixEC80ESP 6S/6MZ302578unaffected
BendixEC80ESP PLCZ266494affected
BendixEC80ESP PLCZ302578unaffected
BendixEC80ESP 2nd CANZ266494affected
BendixEC80ESP 2nd CANZ302578unaffected
BendixEC80ESP CAN GatewayZ266494affected
BendixEC80ESP CAN GatewayZ302578unaffected
BendixEC80ESP 4S/4MZ286098affected
BendixEC80ESP 4S/4MZ302579unaffected
BendixEC80ESP PLCZ286098affected
BendixEC80ESP PLCZ302579unaffected

Weaknesses

  • CWE-121: CWE-121

References