CISA published advisory ICSA-26-211-03 on 30 July, then reissued it on 5 August with the mitigation section revised. The subject is a pair of Toptech Systems units, the RCU II+ and the Multiload II+, in any build dated earlier than 24 November 2025. The agency tags the equipment to the energy sector and records it as deployed worldwide, which is the only geography the document offers. Nothing in it narrows the affected population by region.
The defect, CVE-2026-12562, is the absence of a lock rather than a weak one. A network-accessible port runs a Target Communications Framework service, and it asks for no authentication. Behind it sits a debug interface into the embedded Linux environment that runs the device, at root level. The filesystem can be read and written, running processes can be manipulated, and network interfaces can be reconfigured. CISA's own summary is that an attacker takes full control of the unit and can then reach or alter whatever it is connected to. The classification is CWE-306, missing authentication for a critical function.
Two scores are published, 8.8 under CVSS v3.1 and 8.7 under v4.0, and the more useful part of the vector is the attack vector itself: adjacent, not network. CISA states the vulnerability is not exploitable remotely, and that no public exploitation targeting it has been reported to the agency. That moves the question off the perimeter and onto the segment. Whoever already reaches the controller's network reaches the debug port, whether that is a contractor's laptop, a business VLAN separated in theory only, or a maintenance link left standing after commissioning.
Toptech gives three routes. Put the unit on a closed or segmented network that untrusted traffic cannot reach. Run one of the Vulnerability Removal Tools the vendor distributes. Or install current firmware, which the advisory says means stopping the bay and breaking the Weights and Measures seal, with the configuration backed up before the update begins. One of the removal tool variants, the vendor notes, leaves the seals intact and carries the least operational impact.
That ranking is the part of the advisory worth a second read. The vendor is sorting its own fixes by whether they break a legal metrology seal, and on measurement-critical plant that is a fair proxy for what a fix actually costs. The practical reading is that the expensive part of this remediation was never the software.
The check to run is on build date, not model number. Both products cut at the same date, so an asset register that captures model and firmware family but not the dated build will not answer whether a unit is in scope. Segmentation, meanwhile, is a position rather than a repair: the service still answers, unauthenticated, to anything that reaches the segment. What is left to decide is whether the seal-preserving tool satisfies whoever signs off on the measurement chain, or whether the firmware update waits for the next planned bay shutdown.
Source
- cisa.gov/news-events/ics-advisories/icsa-26-211-03