Toptech Systems RCU II+ and Multiload II+
Plan PatchCVSS 8.8ICS-CERT ICSA-26-211-03Jul 30, 2026
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A missing authentication vulnerability in Toptech Systems RCU II+ (versions before 2025-11-24) and Multiload II+ (versions before 2025-11-24) devices allows attackers on the local network to gain full system control without valid credentials. Successful exploitation could enable an attacker to access or manipulate connected networks and resources, including fuel transaction data, inventory records, and operational parameters.
What this means
What could happen
An attacker on your local network could gain complete control of the RCU II+ or Multiload II+ fuel management device, allowing them to alter transaction data, manipulate fuel inventory records, or disrupt fuel distribution operations.
Who's at risk
Operators of fuel retail systems, truck stops, and fleet fueling stations that use Toptech RCU II+ (retail control unit) or Multiload II+ (bulk fuel loading) devices. Any organization relying on these devices for fuel transaction processing, inventory tracking, or delivery management.
How it could be exploited
An attacker with network access to the device (same subnet or local network) can exploit the authentication weakness to gain administrative control without credentials. Once inside, they can issue commands to alter fuel measurements, pricing, or transaction logs.
Prerequisites
- Network access to RCU II+ or Multiload II+ device on the local network segment
- No valid credentials required
remotely exploitableno authentication requiredlow complexityaffects critical fuel management operationsweak authentication mechanism
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (2)
2 pending
ProductAffected VersionsFix Status
RCU II+<2025-11-24No fix yet
Multiload II+<2025-11-24No fix yet
Remediation & Mitigation
0/3
Do now
0/2RCU II+
WORKAROUNDDownload and run the Vulnerability Removal Tool (VRT) from Toptech's S3 bucket (rcuiip_mliip_vrt.zip or .gz) on affected RCU II+ and Multiload II+ units
HARDENINGMove affected RCU II+ and Multiload II+ devices to a closed or network-segmented environment with no access from untrusted networks or stations
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
RCU II+
HOTFIXInstall the latest firmware on RCU II+ and Multiload II+ units from Toptech's firmware download site after backing up current Multiload configuration
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/e3c3e26d-8988-484a-8549-f29b96de8be5Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.