The National Motor Freight Traffic Association (NMFTA) revealed that a 2024 safety recall for Bendix’s EC80 heavy-truck brake controller, which was publicly attributed to memory corruption issues, also secretly patched a range of severe vulnerabilities. These included a wirelessly exploitable remote code execution flaw. NMFTA senior cybersecurity research engineer Ben Gardiner presented these findings at the Black Hat USA 2026 conference.
The EC80 electronic control unit (ECU) manages anti-lock braking, traction control, and stability in heavy commercial vehicles, communicating via the J2497 powerline databus. In late 2024, three OEMs issued recalls covering approximately 450,000 units after Bendix identified memory corruption issues, which they attributed to line noise on J2497. Gardiner's reverse-engineering of pre- and post-update firmware revealed that the update deleted dozens of functions, within which he found buffer-handling flaws that could crash the ECU and enable remote code execution, a hardcoded password capable of disabling traction control, and another flaw offering a theoretical path to a crash and code execution.
The J2497 databus can be accessed remotely, a technique previously linked to an NMFTA-disclosed vulnerability in 2022, or through a compromised trailer telematics device. NMFTA researchers conducted bench and closed-track road tests, simulating wireless attacks by injecting signals through a truck’s diagnostic port. They observed that triggering a crash at low speeds (below 5 mph and around 9 mph) caused CAN bus traffic to stop entirely, requiring a battery disconnection to recover the ECU. This denial-of-service state consistently resulted in the loss of speedometer, steering assist, shifting, and ABS pulsing.
NMFTA stated that the real-world effects, such as the potential to put a driver at risk of a crash or immobilize a truck for purposes like cargo theft, depend heavily on context. The undisclosed fixes address critical security weaknesses that could have significant operational and safety consequences for heavy commercial vehicles.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A 2024 safety recall for Bendix's EC80 heavy-truck brake controller, which publicly addressed memory corruption issues, also quietly fixed several serious vulnerabilities, including a wirelessly reachable remote code execution flaw. This discovery, detailed at Black Hat USA 2026, highlights hidden security risks in critical vehicle components that could lead to denial-of-service and loss of essential vehicle functions.