PT-2026-82774 · Bendix · Ec80Esp 2Nd Can+9

·

CVE-2026-67560

·

Published

2026-08-27

·

Updated

2026-08-28

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67560

Affected Products

Ec80Esp 2Nd Can
Ec80Esp 4S/4M
Ec80Esp 6S/6M
Ec80Esp Can Gateway
Ec80Esp Plc
Ec80Esp+ 2Nd Can
Ec80Esp+ 6S/6M
Ec80Esp+ Integrated Tpms
Ec80Esp+ J1708
Ec80Esp+ Plc