Search
Find merged stories by title or summary.
Claude AI Builds Pre-Auth RCE Exploit for WAGO PLC to Execute ARM Shellcode Without Credentials
A new demonstration shows that an AI-assisted workflow can port a pre-authentication remote code execution exploit to a vulnerable WAGO programmable logic controller, allowing arbitrary ARM shellcode to run without valid credentials. The research documented by Forescout shows meaningful progress in AI-enabled exploitation of operational technology but also reveals that the process remains expensive, error-prone, and heavily dependent on human reverse-engineering expertise. The experiment targeted CVE-2021-31886, a buffer-overflow vulnerability in the Nucleus FTP server used by certain embedded systems, including affected WAGO PLCs. Claude AI Creates Pre-Auth RCE Exploit for WAGO PLC The flaw occurs because the FTP service fails to adequately validate the length of a username supplied through the USER command.
$536 and 8 Hours: AI Learns to Attack a Different PLC
Experts got Claude to port a PLC exploit, but it cost $536 and 8 hours, and a later AI-generated payload accidentally destroyed the hardware. Forescout researchers just answered a question that’s been hanging over industrial security for a while: can AI actually port a working exploit from one PLC to a different model with no source code and no debugger access? Their report says yes, but the answer comes with a price tag, a lot of researcher hand-holding, and a permanently destroyed piece of hardware. The starting point was CVE-2021-31886, a pre-authentication buffer overflow in the Nucleus FTP server that the team had already exploited on a WAGO 750-852 PLC in earlier research. The goal this time was porting that working exploit to a related but distinct model, the WAGO 750-831, using Claude Code with access to a terminal, Ghidra, and the actual physical device.
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command
You've reached the end of current stories for this search.
