CVE-2026-67560
Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then be used to remotely execute arbitrary code or inject arbitrary CAN bus traffic. This could cause the loss of the ABS function, steering assist, speedometer, and shifting.
Published:Aug 27, 2026
Last Modified:Aug 28, 2026
EPS:Aug 27, 2026
EPSS Score:0.00334
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Bendix
Product
Ec80esp+ 2nd Can
Bendix
Ec80esp+ 2nd Can
Vendor
Bendix
Product
Ec80esp+ 6s/6m
Bendix
Ec80esp+ 6s/6m
Vendor
Bendix
Product
Ec80esp+ Integrated Tpms
Bendix
Ec80esp+ Integrated Tpms
Vendor
Bendix
Product
Ec80esp+ J1708
Bendix
Ec80esp+ J1708
Vendor
Bendix
Product
Ec80esp+ Plc
Bendix
Ec80esp+ Plc
Vendor
Bendix
Product
Ec80esp 2nd Can
Bendix
Ec80esp 2nd Can
Vendor
Bendix
Product
Ec80esp 4s/4m
Bendix
Ec80esp 4s/4m
Vendor
Bendix
Product
Ec80esp 6s/6m
Bendix
Ec80esp 6s/6m
Vendor
Bendix
Product
Ec80esp Can Gateway
Bendix
Ec80esp Can Gateway
Vendor
Bendix
Product
Ec80esp Plc
Bendix
Ec80esp Plc
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
