MEDIUM
Use of Hard-coded Credentials in Bransys ELD
Published Sep 18, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.33%
Description
Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.
Affected products
-
- Version 0StatusaffectedConstraints<1.1.54
- Version 0StatusaffectedConstraints<11.00.00
- Version 1.1.54StatusunaffectedConstraints-
- Version 11.00.00StatusunaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on version 1.1.54 or newer.
Weaknesses (1)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Sep 18, 2026
Updated Sep 18, 2026
Reserved Sep 9, 2026
Link CVE-2026-77960
CISA Vulnrichment
Updated Sep 18, 2026