ICSA-26-211-03
·
Published 2026-07-30
·
View on CISA ICS-CERT ↗
Toptech Systems RCU II+ and Multiload II+
CVSS 8.8
HIGH
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources.
CVEs (1)
Remediations
- Toptech Systems provides two methods for remediating affected RCU II+ and Multiload II+ units: First, move the device to a closed or segmented network without untrusted access.
- Run one of the RCU II+/Multiload II+ Vulnerability Removal Tools (VRT) available at https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip, https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz. *-* This option does not require breaking Weights and Measures seals and has the least operational impact.
- This option does not require breaking Weights and Measures seals and has the least operational impact.
- Install the latest firmware from https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/. *-* This method requires stopping the bay and breaking the W&M seal. Be sure to back up the current ML configuration before performing the firmware update.
- This method requires stopping the bay and breaking the W&M seal. Be sure to back up the current ML configuration before performing the firmware update.
- For questions, contact Toptech Systems Support at [email protected]. Additional details are available in Toptech System's firmware vulnerability notice: https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf.
Affected Vendors
Toptech Systems
Affected Products (2)
Toptech Systems
·
RCU II+
<2025-11-24
Toptech Systems
·
Multiload II+
<2025-11-24
Affected Sectors
Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more