Unauthenticated attackers gain full root control over Toptech Systems RCU II+ devices
An unauthenticated service on Toptech RCU II+ devices allows full root-level control over the underlying Linux environment. Attackers can manipulate files, processes, and network interfaces without any credentials. Immediate network isolation of these devices is required to prevent unauthorized access via the Target Communications Framework (TCF) service.
Summary
Toptech Systems' RCU II+ and Multiload II+ products contain a critical vulnerability that exposes a debug interface to the network. This flaw allows an unauthenticated user to gain full root-level access to the embedded system. The vulnerability is tied to a network-accessible port running a Target Communications Framework (TCF) service which lacks any authentication requirements.
Because the TCF service provides direct interaction with the device's Linux environment, an attacker can perform deep alterations to system behavior. This includes viewing and modifying the filesystem, manipulating active processes, or controlling network interfaces.
Technical details
The vulnerability exists because of a specific configuration in the Target Communications Framework (TCF) service. This service listens on a network-accessible port but does not implement any authentication mechanism to verify the identity of connecting users.
Once an attacker establishes a connection through this unauthenticated port, they are granted access to the device's Linux environment with root privileges. This level of access provides total control over the hardware and its software functions. An attacker can modify system configurations, disrupt running services, or use the device as a pivot point within a network.
Affected products and fixed versions
The following Toptech Systems products are confirmed to be vulnerable:
- RCU II+
- Multiload II+
Specific version numbers for the affected firmware were not provided in the available documentation, though the vulnerability affects the current implementation of the TCF service on these models.
Proof of Concept
A proof-of-concept archive containing files related to the vulnerability is available at https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip.
Why this matters for defenders
The ability to gain root access via a network service without credentials represents a total loss of system integrity and confidentiality. In an industrial or embedded context, the ability to manipulate processes or modify the filesystem can lead to unpredictable device behavior or complete operational failure.
Because the attack vector is unauthenticated, any actor with network visibility to the TCF service port can execute these commands. This makes the vulnerability highly exploitable once a network path is established.
Defender guidance
Defenders should prioritize isolating these devices from untrusted networks. Since the vulnerability stems from a network-accessible service, restricting access to the device's management ports is a primary defense.
- Network Segmentation: Ensure that RCU II+ and Multiload II+ devices are placed on isolated network segments that are not reachable from the public internet or general corporate networks.
- Access Control Lists (ACLs): Implement strict ACLs to ensure only authorized management workstations can communicate with the device's IP addresses.
- Monitor TCF Traffic: Watch for unusual connection attempts or unexpected traffic patterns associated with the Target Communications Framework service.
Sources
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03
- https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip
- https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz
- https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/
- https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf
