Bendix EC80 Truck Brake Controller: 2024 Safety Recall Covertly Patched RCE and DoS Vulnerabilities
Bendix EC80 Truck Brake Controller (TL-2026-1928) is a high-severity software vulnerability, first published 2026-08-07. It has no confirmed attribution, affects Bendix Commercial Vehicle Systems EC80 Advanced ECU (brake controller), maps to 11 MITRE ATT&CK techniques (T1078.001, T1190, T1203), and is covered by 9 detection rules and 13 indicators of compromise.
Key facts for TL-2026-1928
- Threat ID
- TL-2026-1928
- Severity
- HIGH
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-08-07
- Last reviewed
- 2026-08-07
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- transport, trucking-logistics, automotive, critical-infrastructure, supply-chain
- Target regions
- North America, united states of america, canada
- Detection rules
- 9
- Indicators of compromise
- 13
Malware and tooling in Bendix EC80 Truck Brake Controller
Malware and tooling: Bendix ID 9363 firmware update utility, Software-Defined Radio (SDR)
A 2024 NHTSA safety recall of ~445,000 Bendix EC80 electronic brake control units, publicly attributed to J2497 powerline-databus memory corruption, also silently fixed an unpatched wireless remote code execution flaw, buffer-handling issues, a denial-of-service flaw, and a hardcoded password capable of disabling traction control. NMFTA researcher Ben Gardiner disclosed these findings at Black Hat USA 2026 (2026-08-06); none of the fixed flaws ever received a CVE identifier.
How Bendix EC80 Truck Brake Controller works
The Bendix EC80 Advanced ECU is an electronic control unit deployed across roughly 450,000 heavy trucks and trailers (Volvo, Mack, International/Navistar, and PACCAR chassis) that governs anti-lock braking (ABS), automatic traction control (ATC), and electronic stability control (ESC). It communicates with trailer ABS modules over SAE J2497, a powerline-carrier (PLC) protocol branded PLC4TRUCKS that has been fielded since 2001 to avoid adding extra tractor-trailer wiring for ABS warning-light compliance.
In late 2024 Bendix and three downstream OEMs (Volvo, Mack, International, PACCAR) filed NHTSA safety recalls (Bendix 24E-086, ~445,208 units; Volvo 24V-790, 126,649 units; Mack 24V-792, 60,450 units; International 24V-818, 105,276 units; PACCAR 24V-915) covering model years 2020-2025. The public justification was that high electrical noise combined with low PLC signal strength -- more likely on trucks towing multiple trailers -- caused the EC80 to incorrectly process J2497 messages, producing 'incorrect message string length and overflow of memory buffers' that could crash the ECU or degrade ABS/ATC/ESC/collision-mitigation performance. Bendix's remedy was a firmware reprogram distributed via its ID 9363 update utility, with owner notifications beginning December 1, 2024.
At Black Hat USA 2026, NMFTA senior research engineer Ben Gardiner revealed that this same firmware update covertly fixed a distinct set of unpatched security vulnerabilities that were never disclosed or assigned CVE identifiers: a wireless remote code execution flaw reachable via the same remote J2497 attack technique NMFTA first flagged in 2022 (CVE-2022-25922 / CVE-2022-26131, CISA advisory ICSA-22-063-01) or, per SecurityWeek's reporting, via a compromised trailer telematics device pivoting onto the brake-controller bus; additional buffer-handling flaws consistent with the 'overflow of memory buffers' language in the NHTSA filings; a separate denial-of-service flaw; and a hardcoded password that could be used to disable traction control. Gardiner's team reverse-engineered pre- and post-update firmware pulled from three EC80 units, finding 'dozens of functions' deleted in the recall update -- the diffing methodology used to surface the covertly-patched flaws. The team then validated real-world impact through bench testing and closed-track road tests, injecting crafted J2497 signals via software-defined radio through/near the diagnostic port and observing complete CAN bus traffic stoppage at speeds below 5 mph and again around 9 mph -- with confirmed loss of speedometer, steering assist, shifting, and ABS pulsing -- requiring a battery disconnect (dealer tool access in one case) to recover the ECU, consistent with Gardiner's 2023 public demonstration of disabling trailer air brakes with a simple two-wire antenna.
The underlying exposure traces to the 2022 NMFTA/Assured Information Security disclosure that J2497 diagnostic functions have no authentication (CVE-2022-25922, CWE-306, CVSS 3.1 9.1, replay-invocable) and that J2497 receivers are susceptible to remote RF-induced signals from up to 12 feet using $300-$10,000 of equipment (CVE-2022-26131, CWE-1319 Improper Protection Against Electromagnetic Fault Injection, CVSS 3.1 9.8 per NVD / 9.3 per ICS-CERT's AV:A-scoped vector). NMFTA pre-briefed Bendix, two of the three affected OEMs, NHTSA, and Transport Canada before the Black Hat talk; Bendix did not respond to SecurityWeek's request for comment. As of July 16, 2026, NHTSA recall-completion data showed a 0-99% range across the five campaigns, with NMFTA estimating an industry-wide completion plateau around 80% due to lost/sold equipment and underreporting. NMFTA is now pushing SAE working groups toward a next-generation J2497 interface that removes non-essential software/diagnostic functions from the powerline channel, since trailers carrying the legacy protocol remain in service 15-30 years.
MITRE ATT&CK techniques used in TL-2026-1928
Privilege Escalation
Initial Access
T1190 Exploit Public-Facing Application
Execution
T1203 Exploitation for Client Execution
Impact
T1489 Service Stop; T1499.004 Application or System Exploitation; T1565.002 Transmitted Data Manipulation
Credential Access
Resource Development
T1588.002 Tool; T1588.005 Exploits; T1588.006 Vulnerabilities
Reconnaissance
Affected products and versions in Bendix EC80 Truck Brake Controller
- Bendix Commercial Vehicle Systems — EC80 Advanced ECU (brake controller)
Vulnerable versions: Firmware predating the 2024-2025 recall reprogram, installed on model years 2020-2025
Fixed in: Firmware reprogrammed via Bendix update utility ID 9363 - Volvo Trucks / Mack Trucks (Volvo Group) — VNL, VAH, VHD, VNRE (Volvo); Anthem, Granite, TerraPro, Pinnacle (Mack) equipped with Bendix EC80
Vulnerable versions: Model years 2020-2025 equipped with affected Bendix EC80 ECUs
Fixed in: NHTSA recall 24V-790 (Volvo, 126,649 units) and 24V-792 (Mack, 60,450 units) - International (Navistar) — International trucks equipped with Bendix EC80 ECU
Vulnerable versions: Model years 2020-2025
Fixed in: NHTSA recall 24V-818, 105,276 units - PACCAR — Kenworth/Peterbilt trucks equipped with Bendix EC80 ECU
Vulnerable versions: Model years 2020-2025
Fixed in: NHTSA recall 24V-915
Remediation for Bendix EC80 Truck Brake Controller
Patches
- Bendix firmware reprogram via update utility ID 9363, distributed under NHTSA recall 24E-086 and OEM campaigns 24V-790 (Volvo), 24V-792 (Mack), 24V-818 (International), 24V-915 (PACCAR)
Immediate actions
- Apply the Bendix EC80 firmware remedy (update utility ID 9363) at an authorized service center under NHTSA recalls 24E-086 / 24V-790 / 24V-792 / 24V-818 / 24V-915
- Prioritize double/triple-trailer and tanker combinations, where high electrical noise plus low PLC signal strength most reliably trigger the flaw
- Check per-VIN recall completion status via the NHTSA recall lookup; completion rates vary 0-99% across the affected campaigns
Workarounds
- No published workaround for legacy/unpatched trailers beyond limiting physical/RF proximity to the PLC bus during operation
Longer-term hardening
- Support NMFTA's SAE working-group effort toward a next-generation J2497 interface that removes non-essential diagnostic/software functions from the powerline channel
- Restrict or authenticate diagnostic-port and PLC access on legacy trailers (15-30 year service life) that cannot be retrofitted
- Push for CVE issuance and public security advisories whenever safety-relevant firmware fixes are bundled into vehicle recalls, per NMFTA's disclosure position
Weaknesses (CWE) in Bendix EC80 Truck Brake Controller
CWE-120, CWE-787, CWE-798, CWE-400, CWE-306, CWE-1319
Timeline of Bendix EC80 Truck Brake Controller
- SAE J2497 (PLC4TRUCKS) powerline-communications standard is fielded for tractor-trailer ABS signaling, later found to carry the vulnerable diagnostic/message-processing functions.
- NMFTA and Assured Information Security disclose CVE-2022-25922 (unauthenticated J2497 diagnostic replay) and CVE-2022-26131 (RF-induced signal susceptibility) via CISA advisory ICSA-22-063-01.
- Ben Gardiner (NMFTA) publicly demonstrates a simple two-wire antenna sending arbitrary J2497 signals to disable trailer air brakes at NMFTA's Digital Solutions Conference on Cybersecurity in Houston, TX.
- Bendix files NHTSA safety recall 24E-086 for approximately 445,208 EC80 Advanced ECUs, publicly attributing faults to J2497 electrical noise and low signal strength causing memory corruption (incorrect message string length / buffer overflow).
- Volvo (recall 24V-790, 126,649 units) and International (recall 24V-818, 105,276 units) file matching recalls/technical bulletins for trucks equipped with the affected EC80 ECU.
- Mack Trucks files NHTSA recall 24V-792 covering 60,450 units equipped with the affected EC80 ECU.
- Bendix begins mailing owner notification letters for the EC80 recall.
- PACCAR issues its technical bulletin/recall (24V-915) for EC80-equipped Kenworth/Peterbilt trucks.
- Bendix's firmware-reprogramming utility (ID 9363) is rolled out across all four affected OEMs' dealer/service networks as the recall remedy.
- Ben Gardiner and NMFTA present research at Black Hat USA 2026 revealing that the 2024 recall covertly fixed an unpatched wireless RCE flaw, buffer-handling flaws, a DoS flaw, and a hardcoded password that could disable traction control -- none of which received a CVE -- and release a 179-page technical whitepaper.
- SecurityWeek publishes reporting on the disclosure, noting Bendix did not respond to requests for comment and that NMFTA pre-briefed Bendix, NHTSA, Transport Canada, and two of three affected OEMs before going public.
Sources cited for Bendix EC80 Truck Brake Controller
- Truck Brake Controllers Safety Recall Doubled as Hidden Security Fix
- Tractor-Trailer Brake Controllers Vulnerable to Remote Hacker Attacks
- Reversing a Recall: From 'Noise Triggered' to RCE -- Black Hat USA 2026 Whitepaper
- Bendix EC80 Recall: Safety and Security Implications
- NMFTA's Ben Gardiner Shows How Easy It Is to Disable a Truck's Brakes . . . With a Simple Antenna
- ICSA-22-063-01: Trailer Power Line Communications (PLC) J2497
- CVE-2022-26131 Detail
- CVE-2022-25922 Detail
- Bendix Recalls EC80 ECU Over Safety Concerns
- Bendix ECU recall affects over 187K Volvo, Mack trucks
- Widespread ECU recall hits a whopping 105K International trucks
- NHTSA Recalls Data Tracker
- Ben Gardiner - Trailer Shouting: Talking PLC4TRUCKS Remotely with an SDR
Threats related to Bendix EC80 Truck Brake Controller
- AI-Assisted "HTTP Terminator" Uncovers Novel HTTP Desync Techniques and Apache Traffic Server Zero-Day (CVE-2026-63078)
- Multiple Zscaler Client Connector Flaws Enable Remote Code Execution (CVE-2026-59568)
- CVE-2026-23918 — Apache HTTP Server mod_http2 Double Free Enabling Unauthenticated DoS and Possible RCE
- Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws
- F5 Patches Multiple NGINX Vulnerabilities: Heap Overflow, Memory Disclosure, and Use-After-Free (CVE-2026-42533, CVE-2026-60005, CVE-2026-56434)
- SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0)
Detection coverage for TL-2026-1928
As of 2026-08-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1928 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.