CVE-2026-12562

Severity CVSS v4.0:
HIGH
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
30/07/2026
Last modified:
31/07/2026

Description

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated <br /> service that exposes a debug interface granting full root-level access <br /> to the embedded system. This vulnerability stems from a <br /> network-accessible port running a Target Communications Framework (TCF) <br /> service that does not require any authentication, allowing an attacker <br /> to directly interact with the Linux environment that powers the device. <br /> Once connected, an attacker can freely view and modify the filesystem, <br /> manipulate running processes, and control network interfaces, enabling <br /> deep alteration of system behavior.