Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

A Hidden Security Fix Hides in Plain Sight: Bendix’s Truck Brake Controller Recall Exposes Serious Vulnerabilities

In a stunning revelation at the Black Hat USA 2026 conference, a team of researchers from the National Motor Freight Traffic Association (NMFTA) has uncovered a shocking truth behind a recent safety recall for Bendix’s EC80 heavy-truck brake controller. What initially seemed like a routine memory corruption fix has turned out to be a covert security patch that quietly addressed several critical vulnerabilities, including remote code execution and denial-of-service flaws.

The EC80 electronic control unit (ECU) is responsible for handling essential functions such as anti-lock braking, traction control, and stability in heavy commercial vehicles. It communicates over the J2497 powerline databus, a widely used standard that has been the industry’s de facto choice since 2001 to meet federal trailer ABS warning-light requirements.

In late 2024, three Original Equipment Manufacturers (OEMs) that integrated the EC80 issued recalls for an estimated 450,000 units after Bendix identified memory corruption issues. However, researchers have now discovered that the subsequent software update not only fixed the memory corruption problem but also deleted dozens of functions, revealing a plethora of hidden vulnerabilities.

Ben Gardiner, NMFTA’s senior cybersecurity research engineer, reverse-engineered pre- and post-update firmware from three EC80 units and found several security flaws, including buffer-handling issues that could crash the ECU, enable remote code execution, and even disable traction control. Perhaps most concerning is the fact that J2497 can be reached remotely or through a compromised trailer telematics device.

In controlled experiments, NMFTA researchers demonstrated the potential impact of these vulnerabilities by injecting signals into the truck’s diagnostic port using a software-defined radio. The results were stark: once the crash was triggered, CAN bus traffic ceased entirely, and recovering the ECU required disconnecting the battery. This denial-of-service (DoS) state caused significant disruptions to essential functions such as speedometer readings, steering assist, shifting, and ABS pulsing.

While the researchers acknowledged that these vulnerabilities do not directly compromise a driver’s control of the vehicle, they pointed out that the impacts were serious enough for Bendix to issue a recall. Moreover, Gardiner noted that none of the vulnerabilities received a CVE identifier, which may obscure their security significance.

The NMFTA has briefed key stakeholders, including NHTSA and Transport Canada, on its findings, and the team has published a comprehensive technical whitepaper detailing the vulnerabilities. While it’s unclear whether all affected trucks have received the software update, NMFTA is urging drivers to remain vigilant and monitor recall completion rates.

As this story highlights, even seemingly routine safety recalls can conceal critical security vulnerabilities. For those in the industry, it’s essential to maintain a vigilant approach to cybersecurity, ensuring that updates are thoroughly examined for potential security implications.


Source: SecurityWeek — 2026-08-07