Multiple Vulnerabilities in Bransys ELD Affecting Data Privacy
Bransys ELD versions for Android and iOS contain hard-coded credentials and cleartext transmission flaws, allowing unauthorized read access to real-time telemetry data.
Bransys has disclosed multiple vulnerabilities in the Bransys ELD mobile application affecting Android versions prior to 11.00.00 and iOS versions prior to 1.1.54. These vulnerabilities include the use of hard-coded credentials for MQTT (CVE-2026-86520) and FTP (CVE-2026-77960) services, as well as the cleartext transmission of sensitive information (CVE-2026-86689). An attacker with network access to the target broker or server could leverage these credentials to gain unauthorized read access to real-time device telemetry data across a subset of carriers. These flaws represent significant privacy and security risks for transportation systems in the United States where these devices are deployed. There is currently no evidence of active exploitation in the wild.
Impact
Successful exploitation of these vulnerabilities allows unauthorized parties to access sensitive real-time telemetry data and potentially other device information. Given the deployment of these systems in the transportation sector, unauthorized access to fleet data and device information poses operational and privacy risks to the involved carriers.
Recommendation
- Update Bransys ELD to the latest available versions: Android v11.00.00 or higher and iOS v1.1.54 or higher via official app stores.
- Restrict network access to telemetry servers and brokers; ensure these devices are isolated behind firewalls and not directly exposed to the internet.
- Monitor for unauthorized connection attempts or unusual traffic patterns originating from fleet mobile devices toward MQTT or FTP infrastructure.
Immediate actions
Update all instances of Bransys ELD to Android v11.00.00 or iOS v1.1.54
Mitigations
Isolate fleet ELD network communication behind firewalls and VPNs
CVE-2026-86520, CVE-2026-86689, CVE-2026-77960