[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBiw6vhQOYgfnlDiWRPAlGxdnQs6km9TsDWufUIy7Mys":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"8ff5bb81-704c-4c60-9f90-6daa42df0558","Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix","truck-brake-controller-s-safety-recall-doubled-as-hidden-security-fix-45b13c","NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities. The post Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix appeared first on SecurityWeek.","A safety recall for Bendix's EC80 heavy-truck brake controller also patched significant security vulnerabilities, including remote code execution and denial-of-service flaws. NMFTA researchers discovered these hidden fixes while reverse-engineering firmware updates, noting that the vulnerabilities could lead to critical system failures and were not assigned CVE identifiers.","Bendix EC80 brake controller recall fixed RCE and DoS flaws alongside safety issues.","Black Hat — The National Motor Freight Traffic Association (NMFTA) says a 2024 safety recall for Bendix’s EC80 heavy-truck brake controller quietly fixed a set of serious vulnerabilities, including a wirelessly reachable remote code execution flaw, alongside the memory corruption issue Bendix publicly disclosed. The findings were detailed by NMFTA senior cybersecurity research engineer Ben Gardiner on Thursday at the Black Hat USA 2026 conference. The EC80 electronic control unit (ECU) handles anti-lock braking, traction control and stability functions on heavy commercial vehicles. It communicates over J2497, also known as PLC4TRUCKS, a powerline databus that has served since 2001 as the only industry-standard way to meet federal trailer ABS warning-light requirements. SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity In late 2024, three OEMs that integrate the EC80 issued recalls — covering an estimated 450,000 units — after Bendix identified memory corruption issues that could take the ECU offline. Bendix attributed the issue to line noise on J2497 and shipped a fix. Gardiner said he reverse-engineered pre- and post-update firmware from three EC80 units, one from each affected OEM, and found that the update deleted dozens of functions.Advertisement. Scroll to continue reading. Inside that deleted code the researcher identified several vulnerabilities, including buffer-handling flaws that could crash the ECU and enable remote code execution, a hardcoded password that could disable traction control, and a flaw offering a theoretical path to both a crash and code execution. Security implications and potential real-world impact J2497 can be reached remotely — a technique tied to a vulnerability disclosed by NMFTA in 2022 — or through a compromised trailer telematics device. NMFTA researchers tested the potential impact of the new vulnerabilities in a bench environment and, for closed-track road tests, used a software-defined radio to inject signals through a truck’s diagnostic port, simulating a wireless attack. Driving below 5 mph and around 9 mph, they observed that CAN bus traffic stopped entirely once the crash was triggered, and that recovering the ECU always required disconnecting the battery. This denial-of-service (DoS) state consistently caused loss of speedometer, steering assist, and shifting, as well as ABS pulsing. Asked whether those real-world effects could put a driver at risk of a crash or be used to immobilize a truck, for example during a cargo theft operation, NMFTA told SecurityWeek the outcome depends heavily on context. Driver agreements would likely bar operating a truck in the affected state, with NMFTA noting that recovery needs a battery disconnect and, in one case, a dealer tool. However, causing a crash directly isn’t clear-cut because the attacks don’t take away the driver’s control of the vehicle. Nevertheless, NMFTA noted the impacts were serious enough for Bendix to issue a recall. On the other hand, Gardiner noted that none of the vulnerabilities received a CVE identifier despite being fixed, arguing that this may obscure the security significance of what was framed publicly as a safety-only update. NMFTA contacted Bendix and briefed two of the three affected OEMs, along with NHTSA and Transport Canada, before making its findings public. On whether the fix has actually reached affected trucks, NMFTA pointed to NHTSA’s public recall-completion tracker, which on July 16 showed recall completion rates ranging between 0 and 99% for identifiers associated with this recall. NMFTA believes that recall completion rates commonly plateau around 80% industry-wide due to factors like lost equipment and underreporting. After the Black Hat talk, NMFTA published a 179-page technical whitepaper detailing the findings. Bendix has not responded to SecurityWeek’s request for comment. Related: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones Related: Free Wi-Fi Leaves Buses Vulnerable to Remote Hacking Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Meta AI Hacked External Systems During Cybersecurity TestingHow a $50,000 Exploit Chain Turned Bixby Against Samsung Phones New Attack Methods Enable Malware to Hijack Passkey-Protected AccountsCybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data Water Sector Cyberattacks Reportedly Hit at Least 12 StatesTP-Link Omada ZTP Vulnerabilities Chain Into Full Network TakeoverMicrosoft Bug Bounty Program: $20 Million Paid to 500 ResearchersN‑able Patches Vulnerability Exploited to Hack N-central Servers Latest News Black Hat USA 2026 – Summary of Vendor Announcements (Part 4)Microsoft, Apple Release Fresh Security Updates3.8 Million Impacted by Unlimited Technology Systems Data BreachCritical Vulnerabilities Patched With Chrome 151 UpdateSnowflake Hacker Pleads Guilty in US CourtZero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X PostsPodcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna ConwayCritical Paperclip Flaw Allowed Admin Access, Code Execution Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move1Kosmos has named Frank Cohen Chief Revenue Officer.ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.James Wilkinson has been named Chief Information Security Officer for the City of Dallas.More People On The MoveExpert Insights Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Ftruck-brake-controllers-safety-recall-doubled-as-hidden-security-fix\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F11\u002Ftruck-cargo-freight-hacking-transportation.jpeg","2026-08-07T10:00:00+00:00","2026-08-07T10:00:18.186335+00:00",8,[18,21,24,27],{"name":19,"type":20},"EC80","product",{"name":22,"type":23},"Bendix","vendor",{"name":25,"type":26},"J2497","technology",{"name":28,"type":26},"PLC4TRUCKS","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":29,"icon":31,"name":32,"slug":33},null,"Vulnerabilities","vulnerabilities",[35,37,42],{"category":36},{"id":29,"icon":31,"name":32,"slug":33},{"category":38},{"id":39,"icon":31,"name":40,"slug":41},"d6f63bb8-0801-486a-be7f-171400700454","IoT\u002FOT","iot-ot",{"category":43},{"id":44,"icon":31,"name":45,"slug":46},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[48,52,55,58],{"type":49,"value":50,"context":51},"mitre_attack","T1070","Potential for denial of service by crashing the ECU",{"type":49,"value":53,"context":54},"T1071","Wireless communication over J2497 (PLC4TRUCKS)",{"type":49,"value":56,"context":57},"T1547","Hardcoded password for disabling traction control",{"type":49,"value":59,"context":60},"T1059","Remote code execution vulnerability"]