{"id":"CVE-2026-77960","published":"2026-09-18T16:17:09.583","lastModified":"2026-09-18T19:03:28.367","description":"Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwes":["CWE-798"],"vendors":[],"products":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-01.json","tags":[]},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01","tags":[]}],"exploitRefs":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-01.json","tags":[]}],"hasPoc":true,"ai":null}