The National Motor Freight Traffic Association (NMFTA) has uncovered significant security vulnerabilities in the Bendix EC80 brake controller, addressing them quietly alongside a safety recall in 2024. The revelations were made by Ben Gardiner, NMFTA’s senior cybersecurity research engineer, at the Black Hat USA 2026 conference.
Details of the Bendix EC80 Brake Controller
The EC80 electronic control unit (ECU) is crucial for managing anti-lock braking, traction control, and stability in heavy commercial vehicles. It operates using J2497, or PLC4TRUCKS, a powerline databus essential for meeting federal trailer ABS warning-light standards since 2001.
In late 2024, Bendix, along with three original equipment manufacturers (OEMs) integrating the EC80, issued a recall affecting approximately 450,000 units. The recall addressed memory corruption issues that could render the ECU non-operational, attributed to line noise on the J2497, prompting Bendix to release a corrective update.
Unveiling Hidden Vulnerabilities
Gardiner’s research involved reverse-engineering firmware updates from different OEMs, discovering that the updates removed numerous functions. These deletions concealed vulnerabilities such as buffer-handling flaws that could crash the ECU, allow remote code execution, and a hardcoded password that disabled traction control, among others.
The potential real-world impact of these vulnerabilities is significant. J2497 can be accessed remotely or through a compromised trailer telematics device. NMFTA’s testing simulated wireless attacks, revealing that triggered crashes halted CAN bus traffic, requiring a battery disconnect to recover, affecting speedometer, steering, and more.
Implications and Industry Response
While the vulnerabilities are serious, NMFTA emphasizes that their real-world implications depend on context. The necessary recovery steps, including battery disconnection, mitigate direct crash risks, as the driver retains control. Nonetheless, the recall was deemed critical enough for Bendix to proceed.
Despite the importance of the fixes, none of the vulnerabilities received a CVE identifier, a move that Gardiner suggests might obscure their security significance. NMFTA has communicated its findings to Bendix, affected OEMs, and regulatory bodies like NHTSA and Transport Canada.
The recall’s progress can be tracked via NHTSA’s public tracker, which shows completion rates between 0 and 99% as of mid-July 2024. NMFTA notes that industry-wide recall completions often plateau around 80% due to factors like lost equipment and underreporting.
Following the Black Hat presentation, NMFTA released a comprehensive 179-page technical whitepaper detailing their findings. Bendix has yet to comment publicly on these developments.
