Illustrative image generated with AI
Root Access Without Password on Toptech Industrial Devices: Bug Fixed with an Update
CVE-2026-12562 allows unauthenticated root access on Toptech RCU II+ and Multiload II+ controllers. A firmware update and removal tool resolve the flaw.
Text generated by artificial intelligence, published without human review. AI transparency
On July 30, 2026, researcher Donald Green of the Southwest Research Institute reported to CISA a flaw affecting Toptech Systems' RCU II+ and Multiload II+ embedded controllers. Identified as CVE-2026-12562, the vulnerability allows an unauthenticated attacker to gain full control of the device's Linux system simply by reaching its network port from an adjacent location.
An Unauthenticated Debug Service
Both models expose the TCF (Target Communications Framework) service on the network, intended for development and diagnostics. The issue, classified as CWE-306 (Missing Authentication for Critical Function), lies in the complete lack of authentication: anyone who can connect to the dedicated port immediately gets a root shell. No credentials, no victim interaction, no defense mechanisms.
Affected Models and Versions
The flaw affects Toptech Systems' RCU II+ and Multiload II+ devices. The company is a U.S.-based firm active in the energy sector with worldwide distribution. All firmware versions prior to the build dated November 24, 2025, are vulnerable. The vendor has confirmed the issue and made available tools and procedures to fix it.
Operational Impact and CVSS Score
By exploiting CVE-2026-12562, an attacker can read, write, and modify the entire filesystem, alter running processes, manipulate network interfaces, and from there move laterally to other connected resources. The impact on availability, integrity, and confidentiality of the managed industrial processes is maximum. The CVSS v3.1 score is 8.8 (HIGH), vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; the CVSS v4.0 rating stands at 8.7.
Three Paths to Secure the Controllers
In the official advisory, Toptech outlines three options to eliminate the vulnerability:
- Network Isolation – Move devices to closed segments or separate them from untrusted hosts.
- Removal Tool (VRT) – Provided by the vendor via links published in the advisory, it disables the vulnerable service without breaking Weights & Measures seals and with minimal operational impact.
- Firmware Update – The latest release, downloadable from Toptech's portal, fixes the flaw at its root. This method requires stopping the bay and breaking the W&M seal; before proceeding, backing up the Multiload configuration is mandatory.
For questions, the vendor provides the address [email protected]. CISA reiterates the importance of reducing network exposure of industrial control systems, using up-to-date VPNs for remote access, and reporting suspicious activities to the relevant authorities.
Sources
This article is an original reworking based on the sources below.
