{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-12562",
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "state": "PUBLISHED",
        "assignerShortName": "icscert",
        "dateReserved": "2026-06-17T20:31:31.583Z",
        "datePublished": "2026-07-30T21:29:35.378Z",
        "dateUpdated": "2026-07-31T15:39:49.359Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
                "shortName": "icscert",
                "dateUpdated": "2026-07-30T23:58:13.132Z"
            },
            "title": "Toptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical Function",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-306",
                            "description": "CWE-306",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Toptech Systems",
                    "product": "RCU II+",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "2025-11-24",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Toptech Systems",
                    "product": "Multiload II+",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "2025-11-24",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "The RCU II+ and Multiload II+ are vulnerable to an unauthenticated \nservice that exposes a debug interface granting full root-level access \nto the embedded system. This vulnerability stems from a \nnetwork-accessible port running a Target Communications Framework (TCF) \nservice that does not require any authentication, allowing an attacker \nto directly interact with the Linux environment that powers the device. \nOnce connected, an attacker can freely view and modify the filesystem, \nmanipulate running processes, and control network interfaces, enabling \ndeep alteration of system behavior.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "The RCU II+ and Multiload II+ are vulnerable to an unauthenticated \nservice that exposes a debug interface granting full root-level access \nto the embedded system. This vulnerability stems from a \nnetwork-accessible port running a Target Communications Framework (TCF) \nservice that does not require any authentication, allowing an attacker \nto directly interact with the Linux environment that powers the device. \nOnce connected, an attacker can freely view and modify the filesystem, \nmanipulate running processes, and control network interfaces, enabling \ndeep alteration of system behavior."
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip"
                },
                {
                    "url": "https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz"
                },
                {
                    "url": "https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/"
                },
                {
                    "url": "https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf"
                },
                {
                    "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03"
                },
                {
                    "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-03.json"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "ADJACENT_NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH",
                        "baseSeverity": "HIGH",
                        "baseScore": 8.8,
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                    }
                },
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "ADJACENT",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "HIGH",
                        "subConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "HIGH",
                        "subIntegrityImpact": "NONE",
                        "vulnAvailabilityImpact": "HIGH",
                        "subAvailabilityImpact": "NONE",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "HIGH",
                        "baseScore": 8.7,
                        "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "Toptech Systems provides two methods for remediating affected RCU II+ \nand Multiload II+ units: First, move the device to a closed or segmented\n network without untrusted access.\n\n\n\n\nRun one of the RCU II+/Multiload II+ Vulnerability Removal Tools (VRT)\n available at \n https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip ,\n \nhttps://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz.\n \n\n  *  This option does not require breaking Weights and Measures seals and has the least operational impact.\n\n\nInstall the latest firmware from \n https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/ .\n   *  This method requires stopping the bay and breaking the W&M seal. \nBe sure to back up the current ML configuration before performing the \nfirmware update.\n\n\n\nFor questions, contact Toptech Systems Support at security@toptech.com. \nAdditional details are available in Toptech System's firmware \nvulnerability notice: \n https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf .",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<div>Toptech Systems provides two methods for remediating affected RCU II+ \nand Multiload II+ units: First, move the device to a closed or segmented\n network without untrusted access.</div><div><br></div><div>Run one of the RCU II+/Multiload II+ Vulnerability Removal Tools (VRT)\n available at \n<a href=\"https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip\">https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip</a>,\n<a href=\"https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz\"> \nhttps://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz</a>.\n </div><ul><li>This option does not require breaking Weights and Measures seals and has the least operational impact.</li></ul>Install the latest firmware from \n<a href=\"https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/\">https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/</a>.\n <ul><li>This method requires stopping the bay and breaking the W&amp;M seal. \nBe sure to back up the current ML configuration before performing the \nfirmware update.</li></ul><div>\nFor questions, contact Toptech Systems Support at security@toptech.com. \nAdditional details are available in Toptech System's firmware \nvulnerability notice: \n<a href=\"https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf\">https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf</a>.\n\n</div>"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Donald Green of Southwest Research Institute reported this vulnerability to CISA.",
                    "type": "finder"
                }
            ],
            "source": {
                "advisory": "ICSA-26-211-03",
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.4"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-07-31T15:39:39.902412Z",
                                "id": "CVE-2026-12562",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-07-31T15:39:49.359Z"
                }
            }
        ]
    }
}