VORANT. Threat Intelligence Sign in Get the full feed

Bransys ELD apps expose hardcoded MQTT, FTP creds

routine vulnerability transportation

Bransys ELD Android and iOS apps ship hardcoded MQTT/FTP credentials and cleartext data transmission, exposing fleet telemetry to unauthorized access.

CISA published an ICS advisory for Bransys Electronic Logging Device (ELD) mobile applications used in the U.S. transportation sector. Three vulnerabilities affect Android versions before 11.00.00 and iOS versions before 1.1.54: hardcoded MQTT broker credentials (CVE-2026-86520) granting read access to real-time telemetry across a subset of connected carriers, cleartext transmission of sensitive data (CVE-2026-86689) allowing interception of broker traffic, and hardcoded FTP credentials (CVE-2026-77960) allowing unauthorized read access to stored data on the FTP server.

Successful exploitation would let an attacker without prior authentication read live telemetry and firmware-related data from affected devices, potentially exposing vehicle location, driver logs, and other ELD data across multiple carriers sharing the same broker infrastructure. CISA states no public exploitation of these specific vulnerabilities has been reported at this time. The vendor has released fixed versions (Android ≥11.00.00, iOS ≥1.1.54) available via the respective app stores, and CISA recommends standard network isolation practices (segmenting control system networks, avoiding direct internet exposure, and using VPNs for remote access) as compensating controls.

This is a vendor-disclosed vulnerability set affecting a niche but critical-infrastructure-adjacent product category (ELDs used for regulatory compliance in commercial trucking/transportation). Defenders in transportation/logistics should prioritize confirming app versions are updated and audit any exposure of MQTT/FTP services to unauthenticated networks.

Mentioned in this report

Vulnerabilities CVE-2026-77960CVE-2026-86520CVE-2026-86689

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free