View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) iOS <1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) CVSS Vendor Equipment Vulnerabilities v3 7.5 Bransys Bransys ELD Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: United States Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-86520 The affected product is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker. View CVE Details Affected Products Bransys ELD Vendor: Bransys Product Version: Bransys Android: <11.00.00, Bransys iOS: <1.1.54 Product Status: known_affected Remediations Vendor fix Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on v…
Open the source record- Tags
- CISA
- Related exam domains
- CISSP 3: Security Architecture and Engineering; CISM 2: Information Security Risk Management
- Source record id
- /node/25501
- First seen by InfoSec Signals
- 9/23/2026
Exam domain labels come from a keyword heuristic and are study hints, not an official mapping. The summary is the publisher's own text, shortened; the linked record is authoritative.