Bendix EC80 Truck Brake Controller: 2024 Safety Recall Covertly Patched RCE and DoS Vulnerabilities — Threadlinqs Intelligence
As of 2026-08-07, Bendix EC80 Truck Brake Controller: 2024 Safety Recall Covertly Patched RCE and DoS Vulnerabilities is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 13 indicators of compromise.
Threat ID: TL-2026-1928 · Severity: HIGH · Status: ACTIVE · Category: VULNERABILITY
A 2024 NHTSA safety recall of ~445,000 Bendix EC80 electronic brake control units, publicly attributed to J2497 powerline-databus memory corruption, also silently fixed an unpatched wireless remote
The Bendix EC80 Advanced ECU is an electronic control unit deployed across roughly 450,000 heavy trucks and trailers (Volvo, Mack, International/Navistar, and PACCAR chassis) that governs anti-lock braking (ABS), automatic traction control (ATC), and electronic stability control (ESC). It communicates with trailer ABS modules over SAE J2497, a powerline-carrier (PLC) protocol branded PLC4TRUCKS that has been fielded since 2001 to avoid adding extra tractor-trailer wiring for ABS warning-light compliance.
In late 2024 Bendix and three downstream OEMs (Volvo, Mack, International, PACCAR) filed NHTSA safety recalls (Bendix 24E-086, ~445,208 units; Volvo 24V-790, 126,649 units; Mack 24V-792, 60,450 units; International 24V-818, 105,276 units; PACCAR 24V-915) covering model years 2020-2025. The public justification was that high electrical noise combined with low PLC signal strength -- more likely on trucks towing multiple trailers -- caused the EC80 to incorrectly process J2497 messages, producing 'incorrect message string length and overflow of memory buffers' that could crash the ECU or degrade ABS/ATC/ESC/collision-mitigation performance. Bendix's remedy was a firmware reprogram distributed via its ID 9363 update utility, with owner notifications beginning December 1, 2024.
At Black Hat USA 2026, NMFTA senior research engineer Ben Gardiner revealed that this same firmware update covertly fixed a distinct set of unpatched security vulnerabilities that were never disclosed or assigned CVE identifiers: a wireless remote code execution flaw reachable via the same remote J2497 attack technique NMFTA first flagged in 2022 (CVE-2022-25922 / CVE-2022-26131, CISA advisory ICSA-22-063-01) or, per SecurityWeek's reporting, via a compromised trailer telematics device pivoting onto the brake-controller bus; additional buffer-handling flaws consistent with the 'overflow of memory buffers' language in the NHTSA filings; a separate denial-of-service flaw; and a hardcoded password that could be used to disable traction control. Gardiner's team reverse-engineered pre- and post-update firmware pulled from three EC80 units, finding 'dozens of functions' deleted in the recall update -- the diffing methodology used to surface the covertly-patched flaws. The team then validated real-world impact through bench testing and closed-track road tests, injecting crafted J2497 signals via software-defined radio through/near the diagnostic port and observing complete CAN bus traffic stoppage at speeds below 5 mph and again around 9 mph -- with confirmed loss of speedometer, steering assist, shifting, and ABS pulsing -- requiring a battery disconnect (dealer tool access in one case) to recover the ECU, consistent with Gardiner's 2023 public demonstration of disabling trailer air brakes with a simple two-wire antenna.
The underlying exposure traces to the 2022 NMFTA/Assured Information Security disclosure that J2497 diagnostic functions have no authentication (CVE-2022-25922, CWE-306, CVSS 3.1 9.1, replay-invocable) and that J2497 receivers are susceptible to remote RF-induced signals from up to 12 feet using $300-$10,000 of equipment (CVE-2022-26131, CWE-1319 Improper Protection Against Electromagnetic Fault Injection, CVSS 3.1 9.8 per NVD / 9.3 per ICS-CERT's AV:A-scoped vector). NMFTA pre-briefed Bendix, two of the three affected OEMs, NHTSA, and Transport Canada before the Black Hat talk; Bendix did not respond to SecurityWeek's request for comment. As of July 16, 2026, NHTSA recall-completion data showed a 0-99% range across the five campaigns, with NMFTA estimating an industry-wide completion plateau around 80% due to lost/sold equipment and underreporting. NMFTA is now pushing SAE working groups toward a next-generation J2497 interface that removes non-essential software/diagnostic functions from the powerline channel, since trailers carrying the legacy protocol remain in service 15-30 years.
Weaknesses (CWE)
CWE-120, CWE-787, CWE-798, CWE-400, CWE-306, CWE-1319
Target sectors: transport, trucking-logistics, automotive, critical-infrastructure, supply-chain
Target regions: North America, united states of america, canada
Timeline
- SAE J2497 (PLC4TRUCKS) powerline-communications standard is fielded for tractor-trailer ABS signaling, later found to carry the vulnerable diagnostic/message-processing functions.
- NMFTA and Assured Information Security disclose CVE-2022-25922 (unauthenticated J2497 diagnostic replay) and CVE-2022-26131 (RF-induced signal susceptibility) via CISA advisory ICSA-22-063-01.
- Ben Gardiner (NMFTA) publicly demonstrates a simple two-wire antenna sending arbitrary J2497 signals to disable trailer air brakes at NMFTA's Digital Solutions Conference on Cybersecurity in Houston, TX.
- Bendix files NHTSA safety recall 24E-086 for approximately 445,208 EC80 Advanced ECUs, publicly attributing faults to J2497 electrical noise and low signal strength causing memory corruption (incorrect message string length / buffer overflow).
- Volvo (recall 24V-790, 126,649 units) and International (recall 24V-818, 105,276 units) file matching recalls/technical bulletins for trucks equipped with the affected EC80 ECU.
- Mack Trucks files NHTSA recall 24V-792 covering 60,450 units equipped with the affected EC80 ECU.
- Bendix begins mailing owner notification letters for the EC80 recall.
- PACCAR issues its technical bulletin/recall (24V-915) for EC80-equipped Kenworth/Peterbilt trucks.
- Bendix's firmware-reprogramming utility (ID 9363) is rolled out across all four affected OEMs' dealer/service networks as the recall remedy.
- Ben Gardiner and NMFTA present research at Black Hat USA 2026 revealing that the 2024 recall covertly fixed an unpatched wireless RCE flaw, buffer-handling flaws, a DoS flaw, and a hardcoded password that could disable traction control -- none of which received a CVE -- and release a 179-page technical whitepaper.
- SecurityWeek publishes reporting on the disclosure, noting Bendix did not respond to requests for comment and that NMFTA pre-briefed Bendix, NHTSA, Transport Canada, and two of three affected OEMs before going public.
Detections & IOCs
As of 2026-09-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 13 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, T1592.002, T1588.002, T1588.005, T1588.006, T1190, T1203, T1078.001, T1552, T1499.004, T1565.002