CVE-2026-71396: Bendix EC80ESP+ 2nd Can

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.

Affected products

  • Bendix EC80ESP+ 2nd Can: version Z228999 only
  • Bendix EC80ESP+ 6s/6m: version Z228999 only
  • Bendix EC80ESP+ Integrated Tpms: version Z228999 only
  • Bendix EC80ESP+ j1708: version Z228999 only
  • Bendix EC80ESP+ PLC: version Z228999 only
  • Bendix EC80ESP 2nd Can: version Z266494 only
  • Bendix EC80ESP 4s/4m: version Z286098 only
  • Bendix EC80ESP 6s/6m: version Z266494 only
  • Bendix EC80ESP Can Gateway: version Z266494 only
  • Bendix EC80ESP PLC: version Z266494 only; version Z286098 only

Published 2026-08-28. Last modified 2026-08-31.