Recall for Bendix EC80 brake controller fixed remote flaws
A 2024 recall of Bendix’s EC80 brake controller also removed remote-access vulnerabilities, including a wirelessly reachable remote code execution flaw, NMFTA found.
The National Motor Freight Traffic Association (NMFTA) reported that a 2024 safety recall for Bendix’s EC80 heavy-truck electronic control unit (ECU) also removed previously hidden remote-access security flaws. NMFTA engineers reverse-engineered pre- and post-update firmware from recalled units and presented the findings at Black Hat USA 2026.
The recall was issued in late 2024 by three original equipment manufacturers that use the EC80. It covered an estimated 450,000 units after Bendix identified a memory corruption defect that could disable the ECU. Bendix attributed the fault to line noise on the J2497 powerline databus and issued a firmware update to address the problem.
At Black Hat USA 2026, Ben Gardiner, NMFTA senior cybersecurity research engineer, presented the finding: “the update deleted dozens of functions.” NMFTA examined the removed code and identified buffer-handling faults that could crash the ECU and enable remote code execution, a hardcoded password that could disable traction control, and a logic flaw that could lead to a crash or code execution in certain conditions. NMFTA noted that those fixed issues did not receive individual CVE identifiers and that the public notices framed the release as a safety-only update.
The EC80 controls anti-lock braking, traction control and vehicle stability functions on heavy commercial trucks. It communicates over J2497, also known as PLC4TRUCKS, a powerline databus that the industry has used since 2001 to meet federal trailer ABS warning-light requirements. NMFTA outlined two routes an attacker could use to reach J2497: exploiting a previously disclosed vulnerability or compromising a trailer telematics device that is connected to the bus.
To measure real-world impact, NMFTA tested the vulnerabilities in laboratory and closed-track road experiments. Researchers used a software-defined radio to inject signals through a truck’s diagnostic port to simulate a wireless attack. During low-speed runs at about 5 mph and roughly 9 mph, triggering a crash condition caused CAN bus traffic to stop and the ECU to enter a denial-of-service state. Recovery required disconnecting the vehicle battery and in one case required a dealer diagnostic tool.
NMFTA reported that the denial-of-service state led to loss of the speedometer, steering assist, automatic shifting and ABS pulsing. The association said those effects were sufficient for Bendix and the OEMs to issue a recall. NMFTA added that whether the flaws could directly cause a crash depends on circumstances because drivers retained steering and braking control in the tests. The group also warned that the ability to immobilize a truck could be exploited in theft or other crimes.
NMFTA briefed Bendix, two of the affected OEMs, the U.S. regulator and Canadian regulators before making the research public. After the presentation, NMFTA published a 179-page technical whitepaper documenting the findings. Public recall-completion trackers showed completion rates ranging from 0 to 99 percent for related recall identifiers as of mid-July; NMFTA estimated industry recall completion often plateaus near 80 percent because of lost equipment and underreporting. Bendix did not respond to requests for comment.








