---
id: CVE-2026-12562
title: |-
  The RCU II+ and Multiload II+ are vulnerable to an unauthenticated 
  service that exposes a debug interface granting full root-level access 
  to the embedded system
summary: |-
  The RCU II+ and Multiload II+ are vulnerable to an unauthenticated 
  service that exposes a debug interface granting full root-level access 
  to the embedded system. This vulnerability stems from a 
  network-accessible port running a Target…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
published: '2026-07-30'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:30:43.093'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12562'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-03.json
    label: ics-cert@hq.dhs.gov
  - url: >-
      https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/
    label: ics-cert@hq.dhs.gov
  - url: >-
      https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf
    label: ics-cert@hq.dhs.gov
  - url: 'https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz'
    label: ics-cert@hq.dhs.gov
  - url: 'https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00458
epssPercentile: 0.37021
ingestedAt: '2026-09-08T20:10:03.154Z'
---

## Overview

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated 
service that exposes a debug interface granting full root-level access 
to the embedded system. This vulnerability stems from a 
network-accessible port running a Target Communications Framework (TCF) 
service that does not require any authentication, allowing an attacker 
to directly interact with the Linux environment that powers the device. 
Once connected, an attacker can freely view and modify the filesystem, 
manipulate running processes, and control network interfaces, enabling 
deep alteration of system behavior.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
