CVE-2026-77960

Summary

Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

Affected Software

VendorProductVersion RangeStatus
BransysELD0 < 11.00.00affected
BransysELD11.00.00unaffected
BransysELD0 < 1.1.54affected
BransysELD1.1.54unaffected

Weaknesses

  • CWE-798: CWE-798 Use of Hard-coded Credentials

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References