IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Bransys ELD

HIGH
CVSS 7.5
Date 2026-09-17T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware.

// Vulnerabilities (3)

CVE ID CVSS Score Severity Description
CVE-2026-86689 5.9 medium
The affected product is susceptible to cleartext transmission of sensitive information, which could allow an attacker to connect to the broker and read all data.
CVE-2026-77960 5.3 medium
The affected product ships with hardcoded FTP credentials which could allow an attacker to connect to the server and read data.
CVE-2026-86520 7.5 high
The affected product is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

// Remediations (1)

Patch: Bransys recommends that users update their system through the app store. Android users should be on
Bransys recommends that users update their system through the app store. Android users should be on version 11.00.00 or newer. iOS users should be on version 1.1.54 or newer.

// References