Unauthenticated Access Vulnerability in RCU II+ and Multiload II+ by TopTech
CVE-2026-12562
8.7HIGH
What is CVE-2026-12562?
The RCU II+ and Multiload II+ systems are exposed to a serious vulnerability due to an unauthenticated service that allows for exploitation of a debug interface. This service, linked to a Target Communications Framework (TCF) accessible via a network port, does not implement any authentication checks, permitting adversaries to directly access the underlying Linux environment. Once compromised, attackers can observe and modify the filesystem, alter running processes, and control network interfaces, leading to substantial manipulation of the system's operational behavior.
Affected Version(s)
Multiload II+ 0 < 2025-11-24
RCU II+ 0 < 2025-11-24
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Donald Green of Southwest Research Institute reported this vulnerability to CISA.
