What is CVE-2026-12562?
An unauthenticated debug interface in RCU II+ and Multiload II+ devices grants full root-level access via a network-accessible Target Communications Framework (TCF) service. This allows attackers to fully compromise the embedded system. Network access to the affected devices should be restricted immediately.
Azərbaycanca: RCU II+ və Multiload II+ cihazlarında autentifikasiya tələb etməyən debug interfeysi aşkarlanıb. Bu boşluq şəbəkə üzərindən Target Communications Framework (TCF) servisinə icazəsiz tam root səviyyəli giriş imkanı yaradır. Cihazların şəbəkə əlçatanlığı məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What level of access does the vulnerability provide on the devices?
The vulnerability grants unauthorized full root-level access via the network-accessible Target Communications Framework (TCF) service.
What mitigation is recommended?
Network access to the affected devices should be restricted immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.