CVE-2026-12562
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-306
Ausencia de autenticación para una función crítica
Fecha de publicación:
30/07/2026
Última modificación:
30/07/2026
Descripción
*** Pendiente de traducción *** The RCU II+ and Multiload II+ are vulnerable to an unauthenticated <br />
service that exposes a debug interface granting full root-level access <br />
to the embedded system. This vulnerability stems from a <br />
network-accessible port running a Target Communications Framework (TCF) <br />
service that does not require any authentication, allowing an attacker <br />
to directly interact with the Linux environment that powers the device. <br />
Once connected, an attacker can freely view and modify the filesystem, <br />
manipulate running processes, and control network interfaces, enabling <br />
deep alteration of system behavior.
Impacto
Puntuación base 4.0
8.70
Gravedad 4.0
ALTA
Puntuación base 3.x
8.80
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-03.json
- https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/
- https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf
- https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz
- https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03



