CVE-2026-86689 PUBLISHED

Cleartext Transmission of Sensitive Information in Bransys ELD

Assigner: icscert
Reserved: 09.09.2026 Published: 18.09.2026 Updated: 18.09.2026

Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.2

Product Status

Vendor Bransys
Product ELD
Versions Default: unaffected
  • affected from 0 to 11.00.00 (excl.)
  • Version 11.00.00 is unaffected
Vendor Bransys
Product ELD
Versions Default: unaffected
  • affected from 0 to 1.1.54 (excl.)
  • Version 1.1.54 is unaffected

Solutions

Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on version 1.1.54 or newer.

Credits

  • Jaime Lightfoot reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-319 Cleartext transmission of sensitive information CWE