Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Hard‑coded MQTT Credentials in Bransys ELD Enable Unauthorized Telemetry Access (CVE‑2026‑86520/86689/77960)

Bransys ELD Android and iOS apps ship with static MQTT broker credentials that grant read‑only access to real‑time telemetry and firmware. Exploitation could let an attacker harvest fleet data without detection, highlighting gaps in credential management and audit readiness for transportation operators.

LiveThreat™ Intelligence · 📅 September 17, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
cisa.gov

Hard‑coded MQTT Credentials in Bransys ELD (CVE‑2026‑86520, CVE‑2026‑86689, CVE‑2026‑77960) Threaten Telemetry Integrity

What It Is – Bransys ELD mobile applications for Android (< 11.00.00) and iOS (< 1.1.54) ship with hard‑coded MQTT broker credentials. The credentials grant read‑only access to real‑time telemetry and firmware for every device that connects to the broker.

Exploitability – The vulnerability is rated CVSS v3 7.5 (High). No public exploit code has been released, but the presence of static credentials makes remote exploitation trivial for any adversary who discovers the broker endpoint.

Affected Products – Bransys ELD Android client (versions < 11.00.00) and Bransys ELD iOS client (versions < 1.1.54).

Why It Matters for Trust & Control Assurance

  • Credential hygiene – Hard‑coded secrets violate basic access‑control best practices and undermine the ability to demonstrate proper credential lifecycle management across frameworks.
  • Evidence of due diligence – Continuous monitoring of device firmware and telemetry access provides audit‑ready logs that prove you are detecting unauthorized reads.
  • Defensible audit trail – Remediating the flaw and documenting the update process creates concrete evidence for regulators and enterprise buyers who demand a trustworthy supply‑chain posture.

Recommended Actions

  • Deploy the vendor‑provided patches immediately (Android ≥ 11.00.00, iOS ≥ 1.1.54).
  • Conduct an inventory of all Bransys ELD deployments and verify version compliance.
  • Replace any static MQTT credentials with per‑device, short‑lived tokens and enforce TLS encryption for all broker traffic.
  • Enable logging of MQTT subscription activity and integrate those logs into a centralized SIEM for continuous monitoring.

Source: CISA Advisory – ICSA‑26‑260‑01

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →