Post
HIGH

Toptech Systems RCU II+/Multiload II+ Missing Authentication Flaw Rated 8.8

· vulnerability · privilege-escalation · cve

CISA disclosed CVE-2026-12562, a missing-authentication-for-critical-function flaw in Toptech Systems RCU II+ and Multiload II+ controllers, rated 8.8 on CVSSv3.

Successful exploitation could let an attacker gain full control of the device and manipulate connected networks and resources, per the advisory. Affected products are used in the energy sector; versions prior to 2025-11-24 are impacted.