Toptech Systems RCU II+ and Multiload II+ Vulnerability Disclosure
A security vulnerability in Toptech Systems' RCU II+ and Multiload II+ devices could allow unauthorized attackers to gain full control of the systems by exploiting an unsecured debug interface.

English Brief
A security vulnerability in Toptech Systems' RCU II+ and Multiload II+ devices could allow unauthorized attackers to gain full control of the systems by exploiting an unsecured debug interface.
الموجز العربي
الكشف عن ثغرة أمنية في أنظمة Toptech Systems طراز RCU II+ و Multiload II+
ثغرة أمنية في أجهزة RCU II+ و Multiload II+ من شركة Toptech Systems قد تسمح للمهاجمين بالتحكم الكامل في النظام عن طريق استغلال واجهة برمجية غير مؤمنة.
- 1Network Isolation: Move affected units to a segmented, restricted VLAN.
- 2Apply VRT: Download and execute the Vulnerability Removal Tool (VRT) from the official Toptech S3 bucket.
- 3Firmware Update: Backup ML configurations, then perform a manual firmware update to the latest version.
English Advisory
// Intelligence Summary
Toptech Systems has disclosed a vulnerability (CVE-2026-12562) affecting RCU II+ and Multiload II+ units. The issue, classified as CWE-306, involves an unauthenticated Target Communications Framework (TCF) service that permits remote root-level access to the underlying Linux environment of the devices.
التقرير العربي
// ملخص استخباراتي
أعلنت شركة Toptech Systems عن ثغرة أمنية (CVE-2026-12562) تؤثر على وحدات RCU II+ و Multiload II+. تندرج هذه الثغرة تحت التصنيف CWE-306، وتتعلق بخدمة إطار عمل اتصالات الهدف (TCF) التي لا تتطلب مصادقة، مما يسمح بالوصول بصلاحيات الجذر (root) إلى نظام Linux المشغل لهذه الأجهزة.
// Technical Context
The flaw stems from a debug interface running on a network-accessible port that lacks authentication. By connecting to this port, an attacker can bypass traditional security controls, enabling full read/write access to the device filesystem, process manipulation, and network configuration changes.
// السياق التقني
تنتج هذه الثغرة عن واجهة تصحيح أخطاء (debug interface) تعمل على منفذ قابل للوصول عبر الشبكة وتفتقر إلى أي نظام مصادقة. من خلال الاتصال بهذا المنفذ، يمكن للمهاجم تجاوز ضوابط الأمان التقليدية، مما يتيح له الوصول الكامل للقراءة والكتابة لنظام ملفات الجهاز، والتلاعب بالعمليات قيد التشغيل، وتغيير إعدادات الشبكة.
// Exposure Notes
Devices running firmware versions prior to November 24, 2025, are affected. The vulnerability requires network access to the device. While not exploitable from the open internet, it poses a significant risk to internal networks where these industrial controllers reside.
// ملاحظات التعرض
تتأثر الأجهزة التي تعمل بإصدارات برمجية سابقة لتاريخ 24 نوفمبر 2025. تتطلب الثغرة وصولاً إلى الشبكة للوصول إلى الجهاز. على الرغم من أنها غير قابلة للاستغلال عبر الإنترنت المفتوح، إلا أنها تشكل خطراً كبيراً على الشبكات الداخلية التي تتواجد فيها وحدات التحكم الصناعية هذه.
// Defensive Priority
Organizations should prioritize network segmentation to isolate affected controllers from broader enterprise networks. Apply the Vendor Removal Tool (VRT) or perform the mandatory firmware update as detailed in the official Toptech advisory.
// الأولوية الدفاعية
يجب على المؤسسات إعطاء الأولوية لعزل أجهزة التحكم المتأثرة عن شبكات المؤسسة الأوسع. يجب تطبيق أداة إزالة الثغرات (VRT) المقدمة من الشركة المصنعة أو إجراء تحديث البرنامج الثابت (firmware) كما هو موضح في دليل Toptech الرسمي.
Mitigation Checklist
- 1Network Isolation: Move affected units to a segmented, restricted VLAN.
- 2Apply VRT: Download and execute the Vulnerability Removal Tool (VRT) from the official Toptech S3 bucket.
- 3Firmware Update: Backup ML configurations, then perform a manual firmware update to the latest version.
- 4Contact Support: Reach out to [email protected] for further guidance on verifying system integrity.
قائمة إجراءات التخفيف
- 1عزل الشبكة: نقل الأجهزة المتأثرة إلى شبكة محلية افتراضية (VLAN) مقيدة ومعزولة.
- 2تطبيق أداة VRT: قم بتنزيل وتشغيل أداة إزالة الثغرات (VRT) من الرابط الرسمي لشركة Toptech.
- 3تحديث البرنامج الثابت: قم بأخذ نسخة احتياطية من إعدادات ML، ثم قم بإجراء تحديث يدوي للبرنامج الثابت إلى أحدث إصدار.
- 4التواصل مع الدعم: تواصل مع [email protected] للحصول على مزيد من الإرشادات حول التحقق من سلامة النظام.
- https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip
- https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz
# Remediation Checklist for RCU II+ / Multiload II+
1. Network Isolation: Move affected units to a segmented, restricted VLAN.
2. Apply VRT: Download and execute the Vulnerability Removal Tool (VRT) from the official Toptech S3 bucket.
3. Firmware Update: Backup ML configurations, then perform a manual firmware update to the latest version.
4. Contact Support: Reach out to [email protected] for further guidance on verifying system integrity.