CISA Issues Advisory for Three Bransys ELD Vulnerabilities Involving Hardcoded and Cleartext Credentials
The Cybersecurity and Infrastructure Security Agency (CISA) has published advisory ICSA-26-260-01 detailing three vulnerabilities in Bransys Electronic Logging Device (ELD) hardware and associated Android and iOS software. The flaws involve use of hardcoded credentials and cleartext transmission of sensitive information. Successful exploitation could allow unauthorized read access to real-time telemetry data and firmware. Affected versions include Bransys Android <11.00.00 and Bransys iOS <1.1.54. CISA reports the vulnerabilities were reported by Jaime Lightfoot. No public exploitation has been confirmed, but the issues pose a risk to transportation sector critical infrastructure.