LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-12562

Published
CVSS8.8
Severityhigh
WeaknessCWE-306
ExploitedNot in CISA KEV

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service that does not require any authentication, allowing an attacker to directly interact with the Linux environment that powers the device. Once connected, an attacker can freely view and modify the filesystem, manipulate running processes, and control network interfaces, enabling deep alteration of system behavior.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-12562

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-12562.