← All Advisories

RCU II+ and Multiload II+ unauthenticated TCF service exposes root-level access to the embedded Linux environment

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-12562

Key Details

CVECVE-2026-12562
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-09-08
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is adjacent; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-306 (Missing Authentication for Critical Function)

What to Know

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated

service that exposes a debug interface granting full root-level access

to the embedded system. This vulnerability stems from a

network-accessible port running a Target Communications Framework (TCF)

service that does not require any authentication, allowing an attacker

to directly interact with the Linux environment that powers the device.

Once connected, an attacker can freely view and modify the filesystem,

manipulate running processes, and control network interfaces, enabling

deep alteration of system behavior. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-12562
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-12562