Machine-generated analysis · WAYSCloud LLM
RCU II+ and Multiload II+ units released before 2025-11-24 expose an unauthenticated debug interface.
Context
The advisory concerns Toptech Systems RCU II+ and Multiload II+ devices. Versions earlier than 2025-11-24 contain a network-accessible TCF service that grants full root-level access to the embedded Linux system. The devices are deployed worldwide in the energy sector. The advisory recommends moving them to a closed network or using a Vulnerability Removal Tool.
Operator considerations
Check: Verify device firmware version is earlier than 2025-11-24.
Isolate: Place the device on a closed or segmented network without untrusted access.
Patch: Run the Toptech Systems Vulnerability Removal Tool (VRT) provided in the advisory.
Log: Monitor for connections to the unauthenticated TCF service port.
Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources.
The following versions of Toptech Systems RCU II+ and Multiload II+ are affected:
RCU II+
Read the full advisory on CISA →