The record
Written from the 1 report below. Nothing here is unsourced.
- Forescout researchers used Anthropic's Claude to port a working pre-authentication remote code execution exploit from one WAGO programmable logic controller model to another, running attacker-supplied shellcode on live hardware.
- The exploit targets CVE-2021-31886, a 9.8-severity buffer overflow in the Nucleus FTP server reachable over TCP port 21 without authentication, and CERT@VDE says no firmware updates are available for the affected WAGO controllers.
- The final stage of developing the remote code execution took an 8-hour-32-minute session with $535.74 in API costs, required sustained researcher steering, and a later attempt to build a command-and-control implant permanently bricked the PLC.
- Affected models include WAGO 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-885, 750-889, 750-331 and 750-352 on Nucleus V1 firmware, and Siemens states no remediation is planned for Nucleus NET.
- The research matters because it shows AI can lower the expertise and time needed to develop exploits for industrial control systems, a risk US agencies also flagged in an August 19 advisory about AI-generated attack scripts targeting internet-exposed PLCs.
What to watch next
- Owners of vulnerable WAGO controllers should watch for firmware updates or apply the advised mitigations of blocking FTP on port 21, segmenting networks and monitoring traffic
- The potential previously unidentified vulnerability in the FTP command extraction loop found by Claude, which Forescout set aside for separate investigation
- The unaddressed fix status of WAGO 750-882 and 750-885 models, which are absent from the advisory's mitigation and remediation tables
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Forescout
2 quotes · 1 outlet
“One could argue that the same researcher could have achieved the initial RCE port without AI in less time and at lower cost while also keeping the PLC alive”
In the article
…interface (API) usage over an 8-hour-32-minute session. A later session that attempted to extend the exploit into a command-and-control (C2) implant wrote to a flash-mapped memory region, permanently bricking the PLC. " One could argue that the same researcher could have achieved the initial RCE port without AI in less time and at lower cost while also keeping the PLC alive ," Forescout said. Vedere Labs had previously developed a working RCE exploit for the WAGO 750-852, and ported that exploit to a WAGO 750-831 running firmware V01.04.16. The researchers supplied the existing 750-852…
“The more immediate risk is not an agent independently deciding to attack a controller, but an authorized agent taking the wrong action on a physical system where failure has real operational consequences”
In the article
…for CVE-2021-31886, run by The Hacker News on September 1, returned no results, and the flaw is absent from Exploit-DB and Packet Storm. That search indexes repository names and descriptions rather than file contents. " The more immediate risk is not an agent independently deciding to attack a controller, but an authorized agent taking the wrong action on a physical system where failure has real operational consequences ," Forescout said. The CERT@VDE advisory for WAGO lists the following devices as vulnerable to all the flaws in that advisory, including CVE-2021-31886 - - 750-829 (FW16 and earlier) - 750-831/000-00x (FW14 and earlier)…
Coverage1
All filed from IndiaSingle origin
Named Germany · United States · Nucleus · Rockwell Automation · Schneider Electric · WAGO · Anthropic · CERT@VDE · Claude · Department of Energy · Environmental Protection Agency · FBI · Forescout · Forescout Research
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
