Skip to content
Threat Feed

Tag

Transportation

5 briefs RSS
high advisory

Multiple Vulnerabilities in Botslab G980H Dashcams

Botslab G980H dash cameras are impacted by 14 firmware vulnerabilities allowing unauthenticated adjacent network attackers to bypass authentication, hijack sessions, and gain full control over device functionality.

G980H Dashcams +1 ics firmware-vulnerability transportation
2t
high threat

Multiple Vulnerabilities in Bransys ELD Affecting Data Privacy

Bransys ELD versions for Android and iOS contain hard-coded credentials and cleartext transmission flaws, allowing unauthorized read access to real-time telemetry data.

exploited Bransys ELD +1 ics transportation data-privacy cve-2026-86520 cve-2026-86689 cve-2026-77960
1t
critical advisory

Hard-coded Cryptographic Keys in Wärtsilä FOS-Onboard

Wärtsilä FOS-Onboard version 5.07.0923.01 contains hard-coded cryptographic keys in the Update Controller and robot testing framework that could facilitate unauthorized code execution, update deployment, and credential theft.

FOS-Onboard ics transportation patch-management cve-2026-78225 cve-2026-81855
2t
medium threat

NASA Core Flight System Health & Safety Application Denial-of-Service Vulnerability

A high-severity denial-of-service vulnerability, CVE-2026-15352, affects NASA Core Flight System (cFS) Health & Safety (HS) Application versions prior to v7.0.1, allowing an unauthenticated attacker to crash the application via a crafted Housekeeping Telemetry request, leading to service disruption in critical infrastructure sectors like Transportation Systems.

exploited NASA Core Flight System cve vulnerability denial-of-service ics space transportation
1t
critical threat

Critical Vulnerabilities in Hydro-Québec Le Circuit Electrique Charging Station Backend

Multiple critical vulnerabilities, including improper access control (CVE-2026-20744), improper restriction of excessive authentication attempts (CVE-2026-42952), and insufficient session expiration (CVE-2026-44383), affect Hydro-Québec Le Circuit Electrique charging station backend versions prior to June 2026, which if exploited could lead to privilege escalation or denial-of-service impacting critical transportation infrastructure.

exploited Hydro-Québec Le Circuit Electrique charging station backend ics vulnerability denial-of-service privilege-escalation transportation
4t