Toggle light / dark theme

Researchers Use Claude to Port PreAuth RCE Exploit From One PLC Model to Another

Forescout Research — Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware.

The exploit targets CVE-2021–31886, a stack-based buffer overflow in the Nucleus FTP server’s handling of the USER command, which carries a Siemens-assigned CVSS score of 9.8 and is accessible before authentication over TCP port 21.

CERT@VDE says no updates are available for the affected WAGO controllers, and advises owners to disable or block FTP on port 21, enforce segmentation controls, and monitor network traffic for anomalies.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */