Impact
An unauthenticated Target Communications Framework service on the network-accessible port of the RCU II+ and Multiload II+ units exposes a full root-level debug interface. Once connected, an attacker can read and modify the filesystem, terminate or spawn processes, and reconfigure network interfaces. This provides complete control over the embedded Linux environment, allowing a compromised system to be used as a launch point for further attacks or to disrupt critical industrial processes.
Affected Systems
The vulnerability affects Toptech Systems RCU II+ and Multiload II+ industrial control units. No specific firmware or hardware release numbers are listed in the advisory, so all current and potentially future revisions of these products are presumed vulnerable until an update is issued.
Risk and Exploitability
Based on the description, the likely attack vector is remote exploitation over the TCF service port from any network with reachability to the device. The CVSS score of 8.7 indicates high severity, while the EPSS score of 0.00278 indicates a very low probability of exploitation. The advisory does not list the CVE in the CISA KEV catalog. Immediate mitigation is required to prevent an attacker from gaining full system control.
OpenCVE Enrichment