{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-77960/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Bransys ELD (Android \u003c 11.00.00)","Bransys ELD (iOS \u003c 1.1.54)"],"_cs_severities":["high"],"_cs_tags":["ics","transportation","data-privacy","cve-2026-86520","cve-2026-86689","cve-2026-77960"],"_cs_type":"threat","_cs_vendors":["Bransys"],"content_html":"\u003cp\u003eBransys has disclosed multiple vulnerabilities in the Bransys ELD mobile application affecting Android versions prior to 11.00.00 and iOS versions prior to 1.1.54. These vulnerabilities include the use of hard-coded credentials for MQTT (CVE-2026-86520) and FTP (CVE-2026-77960) services, as well as the cleartext transmission of sensitive information (CVE-2026-86689). An attacker with network access to the target broker or server could leverage these credentials to gain unauthorized read access to real-time device telemetry data across a subset of carriers. These flaws represent significant privacy and security risks for transportation systems in the United States where these devices are deployed. There is currently no evidence of active exploitation in the wild.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows unauthorized parties to access sensitive real-time telemetry data and potentially other device information. Given the deployment of these systems in the transportation sector, unauthorized access to fleet data and device information poses operational and privacy risks to the involved carriers.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Bransys ELD to the latest available versions: Android v11.00.00 or higher and iOS v1.1.54 or higher via official app stores.\u003c/li\u003e\n\u003cli\u003eRestrict network access to telemetry servers and brokers; ensure these devices are isolated behind firewalls and not directly exposed to the internet.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized connection attempts or unusual traffic patterns originating from fleet mobile devices toward MQTT or FTP infrastructure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T18:10:58Z","date_published":"2026-09-17T18:10:58Z","id":"https://feed.craftedsignal.io/briefs/2026-09-bransys-eld-vulnerabilities/","summary":"Bransys ELD versions for Android and iOS contain hard-coded credentials and cleartext transmission flaws, allowing unauthorized read access to real-time telemetry data.","title":"Multiple Vulnerabilities in Bransys ELD Affecting Data Privacy","url":"https://feed.craftedsignal.io/briefs/2026-09-bransys-eld-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-77960","version":"https://jsonfeed.org/version/1.1"}