A Hidden Security Fix: Truck Brake Controller’s Safety Recall Quietly Patched Critical Vulnerabilities
A disturbing revelation has emerged from the Black Hat USA 2026 conference, where a senior cybersecurity research engineer from the National Motor Freight Traffic Association (NMFTA) revealed that a 2024 safety recall for Bendix’s EC80 heavy-truck brake controller not only addressed memory corruption issues but also quietly fixed several critical security vulnerabilities. The findings have sparked concerns about the potential impact on commercial vehicle safety and security.
The EC80 electronic control unit (ECU), which handles essential functions such as anti-lock braking, traction control, and stability in heavy commercial vehicles, communicates over J2497, a powerline databus that has been an industry standard since 2001. In late 2024, three Original Equipment Manufacturers (OEMs) issued recalls covering an estimated 450,000 units after Bendix identified memory corruption issues that could take the ECU offline. The company attributed these issues to line noise on J2497 and shipped a fix.
However, NMFTA’s Ben Gardiner reverse-engineered pre- and post-update firmware from three EC80 units and discovered that the update deleted dozens of functions. Upon closer inspection, he found several vulnerabilities, including buffer-handling flaws that could crash the ECU and enable remote code execution. Additionally, a hardcoded password was present, allowing an attacker to disable traction control, while another flaw offered a theoretical path to both a crash and code execution.
The security implications are alarming, as J2497 can be reached remotely or through a compromised trailer telematics device. NMFTA researchers tested the potential impact of these vulnerabilities in a bench environment and on closed tracks, simulating wireless attacks using a software-defined radio. The results showed that once the crash was triggered, the CAN bus traffic stopped entirely, causing loss of speedometer, steering assist, and shifting functions, as well as ABS pulsing.
While it is unclear whether these real-world effects could put a driver at risk of a crash or be used to immobilize a truck during a cargo theft operation, NMFTA noted that the impacts were serious enough for Bendix to issue a recall. Gardiner also pointed out that none of the vulnerabilities received a CVE identifier, which may obscure their security significance.
The fix has not been universally applied yet, as NHTSA’s public recall-completion tracker shows varying completion rates across affected units. NMFTA believes that recall completion rates commonly plateau around 80% industry-wide due to factors like lost equipment and underreporting.
This incident highlights the need for clearer communication between manufacturers and regulators about security vulnerabilities. As a practical takeaway, it is essential for vehicle owners and operators to ensure that their trucks are updated with the latest firmware and follow recommended maintenance schedules to minimize potential risks.
Source: SecurityWeek — 2026-08-07