← Back to Feed

Toptech Systems RCU II+ and Multiload II+

CVE-2026-12562

July 30, 2026 · CISA (US-CERT) · Severity: CRITICAL

Toptech Systems RCU II+ and Multiload II+ contain a missing authentication vulnerability in a debug interface. An unauthenticated TCF service exposes full root-level access, allowing an attacker to fully control the system. The vendor provides vulnerability removal tools and recommends network segmentation as mitigations.

Key Takeaways

  • Unauthenticated TCF service grants root-level access to the embedded system.
  • Attackers can view filesystem, manipulate processes, and control network interfaces.
  • Remediate by network segmentation and running the vulnerability removal tools.
☕ Buy a Coffee