<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Bransys ELD (Android &lt; 11.00.00) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/bransys-eld-android--11.00.00/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 17 Sep 2026 18:10:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/bransys-eld-android--11.00.00/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Vulnerabilities in Bransys ELD Affecting Data Privacy</title><link>https://feed.craftedsignal.io/briefs/2026-09-bransys-eld-vulnerabilities/</link><pubDate>Thu, 17 Sep 2026 18:10:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-bransys-eld-vulnerabilities/</guid><description>Bransys ELD versions for Android and iOS contain hard-coded credentials and cleartext transmission flaws, allowing unauthorized read access to real-time telemetry data.</description><content:encoded><![CDATA[<p>Bransys has disclosed multiple vulnerabilities in the Bransys ELD mobile application affecting Android versions prior to 11.00.00 and iOS versions prior to 1.1.54. These vulnerabilities include the use of hard-coded credentials for MQTT (CVE-2026-86520) and FTP (CVE-2026-77960) services, as well as the cleartext transmission of sensitive information (CVE-2026-86689). An attacker with network access to the target broker or server could leverage these credentials to gain unauthorized read access to real-time device telemetry data across a subset of carriers. These flaws represent significant privacy and security risks for transportation systems in the United States where these devices are deployed. There is currently no evidence of active exploitation in the wild.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities allows unauthorized parties to access sensitive real-time telemetry data and potentially other device information. Given the deployment of these systems in the transportation sector, unauthorized access to fleet data and device information poses operational and privacy risks to the involved carriers.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update Bransys ELD to the latest available versions: Android v11.00.00 or higher and iOS v1.1.54 or higher via official app stores.</li>
<li>Restrict network access to telemetry servers and brokers; ensure these devices are isolated behind firewalls and not directly exposed to the internet.</li>
<li>Monitor for unauthorized connection attempts or unusual traffic patterns originating from fleet mobile devices toward MQTT or FTP infrastructure.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>ics</category><category>transportation</category><category>data-privacy</category><category>cve-2026-86520</category><category>cve-2026-86689</category><category>cve-2026-77960</category></item></channel></rss>