Junglewise Threat Intelligence

CVE-2026-12562: Toptech Systems RCU II+ and Multiload II+ auth bypass in TCF service

CVE-2026-12562 · Severity: high · CVSS 8.8 · Published 2026-07-30

Executive brief

Toptech Systems RCU II+ and Multiload II+ devices, which are used in the energy sector for terminal automation and flow control, contain a security flaw that allows unauthorized access. An attacker on the same local network can bypass security controls to gain full administrative control over the device. This could allow them to disrupt operations, manipulate fuel loading processes, or access sensitive system data.

Technical details

The RCU II+ and Multiload II+ embedded systems expose a Target Communications Framework (TCF) service on a network-accessible port without requiring authentication (CWE-306). This debug interface provides direct, unauthenticated root-level access to the underlying Linux operating system. An attacker with adjacent network access can interact with the TCF service to view or modify the filesystem, manipulate running processes, and reconfigure network interfaces. Toptech Systems has released a Vulnerability Removal Tool (VRT) and updated firmware to address the issue.

Affected products

  • Toptech Systems RCU II+ < 2025-11-24
  • Toptech Systems Multiload II+ < 2025-11-24

Timeline

  • 2026-07-30: advisory: CISA published advisory ICSA-26-211-03
  • 2026-07-30: disclosed

References