importantSYS.SOURCE: The Hacker News• 2026-09-02T13:17:13+05:30
AI-Assisted Exploit Porting: Pre-Auth RCE Transition Between WAGO PLC Models
Researchers demonstrated using Anthropic's Claude AI to port a pre-authentication remote code execution (RCE) exploit from one WAGO PLC model to another, exploiting CVE-2021-31886. The work highlights AI's role in accelerating exploit development for industrial control systems (ICS) and underscores risks to critical infrastructure.
Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware.
The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command
*** END OF TRANSMISSION ***