← Back to Feed
Toptech Systems RCU II+ and Multiload II+
CVE-2026-12562
July 30, 2026 · CISA (US-CERT) · Severity: CRITICAL
Toptech Systems RCU II+ and Multiload II+ contain a missing authentication vulnerability in a debug interface. An unauthenticated TCF service exposes full root-level access, allowing an attacker to fully control the system. The vendor provides vulnerability removal tools and recommends network segmentation as mitigations.
Key Takeaways
- Unauthenticated TCF service grants root-level access to the embedded system.
- Attackers can view filesystem, manipulate processes, and control network interfaces.
- Remediate by network segmentation and running the vulnerability removal tools.