这段文本描述的是一个汽车电子控制单元(ECU)的安全漏洞,属于典型的“先崩溃、后利用”攻击链。以下是专业且通顺的中文翻译,保留了技术术语的准确性: Bendix EC80 制动 ECU 存在基于栈的缓冲区溢出漏洞,攻击者可借此使 ECU 崩溃。通过构造特定负载(payload),攻击者可以远程执行任意代码,或向 CAN 总线注入任意通信帧。这可能导致防抱死制动(ABS)功能失效、转向辅助失效、车速表失效以及换挡功能失效。 --- 术语对照与说明: Bendix EC80 Brake ECU: Bendix 是一家知
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Bendix | EC80ESP+ J1708 | Z228999 | - |
|
| Bendix | EC80ESP+ 6S/6M | Z228999 | - |
|
| Bendix | EC80ESP+ PLC | Z228999 | - |
|
| Bendix | EC80ESP+ 2nd CAN | Z228999 | - |
|
| Bendix | EC80ESP+ Integrated TPMS | Z228999 | - |
|
| Bendix | EC80ESP 6S/6M | Z266494 | - |
|
| Bendix | EC80ESP PLC | Z266494 | - |
|
| Bendix | EC80ESP 2nd CAN | Z266494 | - |
|
| Bendix | EC80ESP CAN Gateway | Z266494 | - |
|
| Bendix | EC80ESP 4S/4M | Z286098 | - |
|
| Bendix | EC80ESP PLC | Z286098 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-68967 | 6.5 MEDIUM | Out-of-bounds Write in Bendix EC80 Brake ECU |
| CVE-2026-71396 | 5.4 MEDIUM | Use of Hard-coded Credentials in Bendix EC80 Brake ECU |
No comments yet