Trucky
Book a call β†’
All resources
β˜… Field Report Β· 20 Β· Cybersecurity

Your Brake Controller's "Safety Recall" Was Also a Cybersecurity Patch. Nobody Told You.

A 2024 Bendix brake controller recall quietly patched hackable flaws nobody disclosed. Here's what carriers need to know about ECU security in 2026.

Trucky Γ— We SecureΒ·August 13, 2026Β·5 min read

If your fleet ran a Bendix EC80 brake controller recall back in 2024, you probably filed it under routine maintenance. New firmware, dealer visit, done. What almost nobody in trucking realized is that the update fixed a lot more than the issue Bendix disclosed publicly.

Researchers at the National Motor Freight Traffic Association reverse-engineered the firmware from before and after that update and found it quietly deleted dozens of functions β€” hiding vulnerabilities that had never been disclosed. The findings were presented this month by NMFTA senior cybersecurity research engineer Ben Gardiner at Black Hat USA 2026, and they are a wake-up call for anyone who still thinks of a truck's brakes as purely mechanical.

Here is what carriers need to understand

This touched an estimated 450,000 trucks

In late 2024, three OEMs that build on the Bendix EC80 electronic control unit β€” which handles anti-lock braking, traction control, and stability functions β€” issued recalls covering roughly 450,000 units. Bendix attributed the problem to line noise on J2497, the powerline databus that has served since 2001 as the industry-standard way to meet federal trailer ABS warning-light requirements, and shipped a firmware fix.

The recall description left out the real story

Bendix's public disclosure described a memory corruption issue that could take the ECU offline. What it did not mention: buffer-handling flaws in that same code that could crash the unit and enable remote code execution, a hardcoded password capable of disabling traction control, and a separate flaw with a theoretical path to both a crash and code execution.

It doesn't require physical access

J2497 can be reached remotely, a path tied to a separate vulnerability NMFTA disclosed back in 2022, or through a compromised trailer telematics device. In closed-track testing, NMFTA researchers used a software-defined radio to inject signals through a truck's diagnostic port, simulating a wireless attack. At speeds around 5 to 9 mph, triggering the flaw stopped CAN bus traffic entirely, and every recovery required disconnecting the battery. Trucks lost their speedometer, steering assist, and shifting, with the ABS pulsing throughout.

None of it got a CVE

Despite being fixed, none of the newly-found vulnerabilities received a CVE identifier. Gardiner argued this framing, as a safety-only update, may have obscured how serious the fix actually was β€” leaving fleet IT and security teams with no reliable way to know their trucks were ever exposed.

The recall itself may not be finished

NMFTA pointed to NHTSA's public recall-completion tracker, which as of mid-July showed completion rates ranging from 0% to 99% depending on the specific recall identifier. Industry-wide, recall completion commonly plateaus around 80% due to factors like lost or resold equipment and underreporting.

What carriers can do now

  • β˜…Stop treating "safety recall" and "security patch" as separate categories. If a recall touches software or an ECU, ask your OEM or dealer directly whether it also closes a security gap.
  • β˜…Check NHTSA's recall-completion data for your VINs and confirm every affected unit actually received the 2024 EC80 fix, not just the ones that came in for other service.
  • β˜…Ask your telematics vendor about trailer-side device security, since a compromised telematics unit is one documented path into this bus.
  • β˜…Add electronic control units, not just laptops and servers, to your fleet's asset inventory and vulnerability tracking.
  • β˜…Loop your maintenance team into cybersecurity conversations. In this story, the fix was sitting inside a shop appointment the whole time.

Trucking has spent the last few years learning that phishing emails and fake load board logins can drain a fleet's bank account. This story is the next chapter: the exploit doesn't need to touch your inbox at all. It can live inside the wiring that stops the truck.

Source: Eduard Kovacs, "Truck Brake Controller's Safety Recall Doubled as Hidden Security Fix," SecurityWeek, August 7, 2026.

Free exposure check

See what an attacker sees on your fleet tonight.

No pitch. 72-hour reply. We map your real exposure β€” ELD endpoints, broker logins, leaked credentials, GPS anomalies. Visit /threat-console.

β˜… Want this implemented for your fleet?

Book a 30-minute strategy call.

Walk away with a plan β€” even if we never work together.

Book a call β†’