Status: NEW | Advisory ID: CVE-2026-12562
| CVE | CVE-2026-12562 |
| CVSS Score / Version | 8.8 (High) / CVSS v3.1 |
| Updated | 2026-09-08 |
| CVSS Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is adjacent; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Classified as | CWE-306 (Missing Authentication for Critical Function) |
The RCU II+ and Multiload II+ are vulnerable to an unauthenticated
service that exposes a debug interface granting full root-level access
to the embedded system. This vulnerability stems from a
network-accessible port running a Target Communications Framework (TCF)
service that does not require any authentication, allowing an attacker
to directly interact with the Linux environment that powers the device.
Once connected, an attacker can freely view and modify the filesystem,
manipulate running processes, and control network interfaces, enabling
deep alteration of system behavior. (NVD)
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-12562 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-12562 |