CVE-2026-12562
Severity CVSS v4.0:
HIGH
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
30/07/2026
Last modified:
31/07/2026
Description
The RCU II+ and Multiload II+ are vulnerable to an unauthenticated <br />
service that exposes a debug interface granting full root-level access <br />
to the embedded system. This vulnerability stems from a <br />
network-accessible port running a Target Communications Framework (TCF) <br />
service that does not require any authentication, allowing an attacker <br />
to directly interact with the Linux environment that powers the device. <br />
Once connected, an attacker can freely view and modify the filesystem, <br />
manipulate running processes, and control network interfaces, enabling <br />
deep alteration of system behavior.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-03.json
- https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/
- https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf
- https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz
- https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03



