Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-12562

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-306 Ausencia de autenticación para una función crítica
Fecha de publicación:
30/07/2026
Última modificación:
30/07/2026

Descripción

*** Pendiente de traducción *** The RCU II+ and Multiload II+ are vulnerable to an unauthenticated <br /> service that exposes a debug interface granting full root-level access <br /> to the embedded system. This vulnerability stems from a <br /> network-accessible port running a Target Communications Framework (TCF) <br /> service that does not require any authentication, allowing an attacker <br /> to directly interact with the Linux environment that powers the device. <br /> Once connected, an attacker can freely view and modify the filesystem, <br /> manipulate running processes, and control network interfaces, enabling <br /> deep alteration of system behavior.