Root Access Without Password on Toptech Industrial Devices: Bug Fixed with an Update
Vulnerabilities

Illustrative image generated with AI

Root Access Without Password on Toptech Industrial Devices: Bug Fixed with an Update

CVE-2026-12562 allows unauthenticated root access on Toptech RCU II+ and Multiload II+ controllers. A firmware update and removal tool resolve the flaw.

Text generated by artificial intelligence, published without human review. AI transparency

On July 30, 2026, researcher Donald Green of the Southwest Research Institute reported to CISA a flaw affecting Toptech Systems' RCU II+ and Multiload II+ embedded controllers. Identified as CVE-2026-12562, the vulnerability allows an unauthenticated attacker to gain full control of the device's Linux system simply by reaching its network port from an adjacent location.

An Unauthenticated Debug Service

Both models expose the TCF (Target Communications Framework) service on the network, intended for development and diagnostics. The issue, classified as CWE-306 (Missing Authentication for Critical Function), lies in the complete lack of authentication: anyone who can connect to the dedicated port immediately gets a root shell. No credentials, no victim interaction, no defense mechanisms.

Affected Models and Versions

The flaw affects Toptech Systems' RCU II+ and Multiload II+ devices. The company is a U.S.-based firm active in the energy sector with worldwide distribution. All firmware versions prior to the build dated November 24, 2025, are vulnerable. The vendor has confirmed the issue and made available tools and procedures to fix it.

Operational Impact and CVSS Score

By exploiting CVE-2026-12562, an attacker can read, write, and modify the entire filesystem, alter running processes, manipulate network interfaces, and from there move laterally to other connected resources. The impact on availability, integrity, and confidentiality of the managed industrial processes is maximum. The CVSS v3.1 score is 8.8 (HIGH), vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; the CVSS v4.0 rating stands at 8.7.

Three Paths to Secure the Controllers

In the official advisory, Toptech outlines three options to eliminate the vulnerability:

  1. Network Isolation – Move devices to closed segments or separate them from untrusted hosts.
  2. Removal Tool (VRT) – Provided by the vendor via links published in the advisory, it disables the vulnerable service without breaking Weights & Measures seals and with minimal operational impact.
  3. Firmware Update – The latest release, downloadable from Toptech's portal, fixes the flaw at its root. This method requires stopping the bay and breaking the W&M seal; before proceeding, backing up the Multiload configuration is mandatory.

For questions, the vendor provides the address [email protected]. CISA reiterates the importance of reducing network exposure of industrial control systems, using up-to-date VPNs for remote access, and reporting suspicious activities to the relevant authorities.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Related topicsToptech SystemsCVE-2026-12562RCU II+Multiload II+industrial controllersroot access vulnerabilityfirmware updateCISA advisory
Back to home