Description
The RCU II+ and Multiload II+ are vulnerable to an unauthenticated
service that exposes a debug interface granting full root-level access
to the embedded system. This vulnerability stems from a
network-accessible port running a Target Communications Framework (TCF)
service that does not require any authentication, allowing an attacker
to directly interact with the Linux environment that powers the device.
Once connected, an attacker can freely view and modify the filesystem,
manipulate running processes, and control network interfaces, enabling
deep alteration of system behavior.
Published: 2026-07-30
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated Target Communications Framework service on the network-accessible port of the RCU II+ and Multiload II+ units exposes a full root-level debug interface. Once connected, an attacker can read and modify the filesystem, terminate or spawn processes, and reconfigure network interfaces. This provides complete control over the embedded Linux environment, allowing a compromised system to be used as a launch point for further attacks or to disrupt critical industrial processes.

Affected Systems

The vulnerability affects Toptech Systems RCU II+ and Multiload II+ industrial control units. No specific firmware or hardware release numbers are listed in the advisory, so all current and potentially future revisions of these products are presumed vulnerable until an update is issued.

Risk and Exploitability

Based on the description, the likely attack vector is remote exploitation over the TCF service port from any network with reachability to the device. The CVSS score of 8.7 indicates high severity, while the EPSS score of 0.00278 indicates a very low probability of exploitation. The advisory does not list the CVE in the CISA KEV catalog. Immediate mitigation is required to prevent an attacker from gaining full system control.

Generated by OpenCVE AI on August 3, 2026 at 10:24 UTC.

Remediation

Vendor Solution

Toptech Systems provides two methods for remediating affected RCU II+ and Multiload II+ units: First, move the device to a closed or segmented network without untrusted access. Run one of the RCU II+/Multiload II+ Vulnerability Removal Tools (VRT) available at https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip , https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz. * This option does not require breaking Weights and Measures seals and has the least operational impact. Install the latest firmware from https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/ . * This method requires stopping the bay and breaking the W&M seal. Be sure to back up the current ML configuration before performing the firmware update. For questions, contact Toptech Systems Support at security@toptech.com. Additional details are available in Toptech System's firmware vulnerability notice: https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf .


OpenCVE Recommended Actions

  • Move the device to a closed or segmented network with no external untrusted access
  • Use the provided Vulnerability Removal Tool (VRT) to eliminate the debug interface without disrupting operations
  • Backup the current configuration and perform a firmware update from the vendor’s latest download, terminating the bay and breaking the Weights and Measures seal if full functionality is required

Generated by OpenCVE AI on August 3, 2026 at 10:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Toptech Systems
Toptech Systems multiload Ii+
Toptech Systems rcu Ii+
Vendors & Products Toptech Systems
Toptech Systems multiload Ii+
Toptech Systems rcu Ii+

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service that does not require any authentication, allowing an attacker to directly interact with the Linux environment that powers the device. Once connected, an attacker can freely view and modify the filesystem, manipulate running processes, and control network interfaces, enabling deep alteration of system behavior.
Title Toptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Toptech Systems Multiload Ii+ Rcu Ii+
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-31T15:39:49.359Z

Reserved: 2026-06-17T20:31:31.583Z

Link: CVE-2026-12562

cve-icon Vulnrichment

Updated: 2026-07-31T15:39:45.677Z

cve-icon NVD

Status : Received

Published: 2026-07-30T22:16:53.343

Modified: 2026-07-31T16:16:57.663

Link: CVE-2026-12562

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:30:18Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function