Unauthenticated Access Vulnerability in RCU II+ and Multiload II+ by TopTech
CVE-2026-12562

8.7HIGH

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-12562?

The RCU II+ and Multiload II+ systems are exposed to a serious vulnerability due to an unauthenticated service that allows for exploitation of a debug interface. This service, linked to a Target Communications Framework (TCF) accessible via a network port, does not implement any authentication checks, permitting adversaries to directly access the underlying Linux environment. Once compromised, attackers can observe and modify the filesystem, alter running processes, and control network interfaces, leading to substantial manipulation of the system's operational behavior.

Affected Version(s)

Multiload II+ 0 < 2025-11-24

RCU II+ 0 < 2025-11-24

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Donald Green of Southwest Research Institute reported this vulnerability to CISA.
.