CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

Boston police tested Motorola and Axon readers as Flock exited

Cybersecurity

Leapmotor EVs carry cameras from a supplier Australia banned

Policy & Compliance

BYD rewrites Australian privacy policy after Four Corners questions

Cybersecurity

A passwordless port let a researcher command a moving BYD ute

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Hardcoded keys in a truck logging app expose fleet telemetry

A CISA advisory says hardcoded broker and FTP credentials in Bransys logging software let unauthenticated attackers read live telemetry from commercial fleets.

CarThreat Staff
Last updated: September 18, 2026 1:19 am
By
ctadmin
2 Min Read
SHARE

Bransys, a maker of electronic logging devices for commercial truck fleets, shipped its companion app with credentials baked into the binary. A CISA advisory published September 17 describes three flaws that let anyone reaching the company’s brokers read live telemetry from every active unit.

The worst is CVE-2026-86520, an 8.7 under CVSS 4.0. Hardcoded MQTT credentials grant read access to real-time data across a subset of carriers tied to the affected broker. CVE-2026-86689 covers cleartext transmission, which CISA says lets an attacker connect and pull everything flowing through. A third bug, CVE-2026-77960, leaves hardcoded FTP credentials in place, opening a second server to unauthenticated reads.

All three trace to basic hygiene failures, CWE-798 for embedded credentials and CWE-319 for the plaintext channel. CISA lists the sector as Transportation Systems, deployed in the United States.

The exposure is narrow. No code execution, no truck control, no path to the engine. What an attacker gets is location and status data for commercial vehicles, the kind regulators treat as sensitive because it reveals routes, schedules and driver behavior.

Bransys fixed the flaws through app store releases. Android needs version 11.00.00 or newer, iOS 1.1.54. Older installs stay vulnerable until a driver updates, so fleets that manage devices centrally should push the fix rather than wait.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Connected VehiclesData PrivacyFirmware SecurityTelematics Control Units (TCU)Threat IntelligenceVulnerabilities
SOURCES:CISA ICS Advisory ICSA-26-260-01
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Developer workstation showing code analysis for QNX embedded systems
Cybersecurity

Unlocking QNX IFS Images for Binary Whitelisting in Automotive Embedded Systems

By
ctadmin
May 25, 2026
Cybersecurity

Vehicles are getting their own offline AI brain thanks to FEV and Microsoft

By
ctadmin
July 12, 2026
Cybersecurity

Mercedes Benz Telemetry Data Replaces Manual Road Surveys for Infrastructure Safety

By
ctadmin
July 21, 2026
Cybersecurity

Researchers weaponize digital license plates against plate readers

By
ctadmin
August 10, 2026
Car NewsCybersecurity

Critical buffer overflow in EV charging protocol puts vehicles at risk

By
ctadmin
July 18, 2026
Cybersecurity

Automotive cyber incidents hit 477 in Q2 as in-vehicle attacks surge 30%

By
ctadmin
July 21, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?