Home       Speakers       Schedule       Hotel & Travel       Sponsor Now       Media Toolkit       Register Now

NCC-Logo_Green_WhtNMFTA

September 29-October 2 | Long Beach, CA

Project Update EC80

DATE:
Thursday, October 1
TIME:
9:30-10:15 am
LOCATION:
Tichenor

DURATION:
45 minutes

Tractor brake controllers are assumed to be isolated from the trailer's noisy powerline network. This research proves that assumption false. In 2024, a major North American recall was issued for Bendix EC80 brake controllers, citing "memory corruption from power-line noise" as the cause. The power-line in question is the J2497 (PLC4TRUCKS) vehicle network, which is wirelessly accessible via CVE-2022-26131. By reverse-engineering the S12X microcontroller recall firmware and performing binary differential analysis of the update across three affected Truck OEMs, we discovered that the update did more than filter noise: it removed code containing critical vulnerabilities in data parsing and interrupt handling.

We will demonstrate that the removed code contained flaws allowing for Denial-of-Service (DoS) and Remote Code Execution (RCE) on the tractor's primary brake controller—bridging the gap from the trailer network to safety-critical tractor systems. We validated these vulnerabilities on a test bench and in a moving truck, where exploitation caused the loss of the speedometer, dynamic steering, and automatic shifting. Our findings confirm that this safety recall was effectively a silent security patch for a massive legacy codebase. We are releasing the IDA Pro analysis scripts and QBinDiff configurations we developed to conquer the S12X banked-memory nightmare. While Bendix's proactive recall is a commendable safety action, the absence of associated CVEs obscures the critical security nature of the fix from the 450,000+ affected users.
 

Speaker

BenGardiner-Glitch

Ben Gardiner

Senior Cybersecurity Research Engineer, NMFTA

Ben is a cybersecurity researcher and systems engineer with deep expertise in low-level operating systems, embedded systems, and hardware security, bringing experience from global security assurance and reverse engineering roles, leadership across major automotive and transportation cybersecurity standards bodies including SAE and ISO, and presentations at leading cybersecurity events such as DEF CON, Cyber Truck Challenge, Hack in Paris, and HackFest.

Related Sessions

NCC-Logo_Green_WhtNMFTA

September 29-October 2 | Long Beach, CA

Stay in the loop. Sign up for the #NMFTACyber Newsletter to get first access to news on speakers, sessions, cyber insights, and more.

PoweredBy-NMFTA-Wht-1

 The NMFTA Cybersecurity Conference is owned by the National Motor Freight Traffic Association, Inc.® (NMFTA)®

1001 N. Fairfax Street, Suite 600 Alexandria, VA 22314-1798      (866) 411-6632