{"id":2640,"date":"2026-09-02T08:39:40","date_gmt":"2026-09-02T08:39:40","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2640"},"modified":"2026-09-02T08:39:40","modified_gmt":"2026-09-02T08:39:40","slug":"researchers-use-claude-to-port-pre-auth-rce-exploit-from-one-plc-model-to-another","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2640","title":{"rendered":"Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhlWf4d2lnMsRXbG_XpDaQ8uxTM9SD8QBArFea3LdD93t2xnpO4Bw2K_iBewRfrscbj2Kfe6DSkFozbxWnHwMeR5p1cx2XksAyZD5_avLwxqx5L6tvTf_Z807niMu_uqzbslMMgMx8M1IVY9y20gbuDwbWAco96weFLycq2JCQMQ2hpcTnd2yanypqsj4k\/s1700-nu-rw-lo-l85-e365\/claude.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Forescout Research &#8211; Vedere Labs said it used Anthropic&#8217;s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware.<\/p>\n<p>The exploit targets<strong> CVE-2021-31886<\/strong>, a stack-based buffer overflow in the Nucleus FTP server&#8217;s handling of the USER command, which carries a Siemens-assigned CVSS score of 9.8 and is accessible before authentication over TCP port 21.<\/p>\n<p>CERT@VDE says no updates are available for the affected WAGO controllers, and advises owners to disable or block FTP on port 21, enforce segmentation controls, and monitor network traffic for anomalies.<\/p>\n<p>The port required sustained researcher steering, and the final RCE development stage consumed $535.74 in application programming interface (API) usage over an 8-hour-32-minute session.<\/p>\n<p>A later session that attempted to extend the exploit into a command-and-control (C2) implant wrote to a flash-mapped memory region, permanently bricking the PLC.<\/p>\n<p>\u00abOne could argue that the same researcher could have achieved the initial RCE port without AI in less time and at lower cost while also keeping the PLC alive,\u00bb Forescout said.<\/p>\n<p>Vedere Labs had previously developed a working RCE exploit for the WAGO 750-852, and <a href=\"https:\/\/www.forescout.com\/blog\/can-ai-create-plc-attacks-yes-but-it%E2%80%99s-not-that-easy-yet\/\" target=\"_blank\">ported that exploit<\/a> to a WAGO 750-831 running firmware V01.04.16.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The researchers supplied the existing 750-852 exploit, a firmware binary for the 750-831, and a physical 750-831 as the live target. Each stage ran as interactive sessions between a researcher and Claude Code, which had access to a terminal, the reverse-engineering tool Ghidra, and the target PLC.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The work began on Claude Sonnet 4.6 and moved to Claude Opus 4.6 after the initial RCE attempts stalled. Normal FTP processing on the 750-831 zeroed 256 bytes at the attacker-controlled buffer, so the injected shellcode was overwritten before it could run.<\/p>\n<p>Claude adapted the USER and QUIT sequence used against the 750-852 into a USER and CWD sequence. Omitting the CRLF terminator then \u00abprevented the relevant processing path from completing in the usual way,\u00bb Forescout said. The buffer survived long enough for the payload to execute.<\/p>\n<p>Once code execution was established, the model moved from working no-operation (NOP) shellcode to two functional payloads in 12 minutes, Forescout said. One sent ICMP echo requests to an attacker-controlled system, and the other sent a UDP packet containing the string PWNED.<\/p>\n<p>The exploit runs in the Ethernet receive callback context, and the demonstrated capability stops at the point of sending network packets.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgYky7OHBD1ENaLTUGt0lx8TsqJN6swbz1t0eC9sCnjL1CYBrbL-dgQblq8eygYLMyUGxdv6jB1NgpjKqKFLbiyIId2KD5GpVyhXvFiADC29nnmGoatinVzrssTelUzOT4VBife4o4aqiDEy63Hu4OtRzplyVpp8AQRP9X5vnqe73DxFxg6lCMP330ukcM\/s1700-nu-rw-lo-l85-e365\/pip.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgYky7OHBD1ENaLTUGt0lx8TsqJN6swbz1t0eC9sCnjL1CYBrbL-dgQblq8eygYLMyUGxdv6jB1NgpjKqKFLbiyIId2KD5GpVyhXvFiADC29nnmGoatinVzrssTelUzOT4VBife4o4aqiDEy63Hu4OtRzplyVpp8AQRP9X5vnqe73DxFxg6lCMP330ukcM\/s1700-nu-rw-lo-l85-e365\/pip.jpg\" alt=\"\" border=\"0\" data-original-height=\"1193\" data-original-width=\"1388\"\/><\/a><\/div>\n<p>Vedere Labs has previously shown that RCE on a controller can be chained to enable deep lateral movement in operational technology (OT) networks, exploiting multiple vulnerabilities in Schneider Electric Modicon PLCs.<\/p>\n<p>Forescout said the model also flagged a potential bug in the FTP command extraction loop, distinct from CVE-2021-31886, during the first session.<\/p>\n<p>Manual review \u00absuggested that this may be a separate, previously unidentified, vulnerability,\u00bb Forescout said. The team set it aside for separate investigation, and the issue carries no CVE identifier.<\/p>\n<p>A GitHub repository search for <strong>CVE-2021-31886<\/strong>, run by The Hacker News on September 1, returned no results, and the flaw is absent from Exploit-DB and Packet Storm. That search indexes repository names and descriptions rather than file contents.<\/p>\n<p>\u00abThe more immediate risk is not an agent independently deciding to attack a controller, but an authorized agent taking the wrong action on a physical system where failure has real operational consequences,\u00bb Forescout said.<\/p>\n<p>The <a href=\"https:\/\/certvde.com\/en\/advisories\/VDE-2021-050\/\" target=\"_blank\">CERT@VDE advisory for WAGO<\/a> lists the following devices as vulnerable to all the flaws in that advisory, including CVE-2021-31886 &#8211;<\/p>\n<ul>\n<li>750-829 (FW16 and earlier)<\/li>\n<li>750-831\/000-00x (FW14 and earlier)<\/li>\n<li>750-852 (FW16 and earlier)<\/li>\n<li>750-880\/0xx-xxx (FW16 and earlier)<\/li>\n<li>750-881 (FW16 and earlier)<\/li>\n<li>750-882 (FW16 and earlier)<\/li>\n<li>750-885\/0xx-xxx (FW16 and earlier)<\/li>\n<li>750-889 (FW16 and earlier)<\/li>\n<li>750-331 (FW16 and earlier)<\/li>\n<li>750-352\/xxx-xxx (FW16 and earlier)<\/li>\n<\/ul>\n<p>\u00abThe listed fieldbus coupler and PLCs above are based on Nucleus V1 RTOS. At the moment, there are no updates for this version available,\u00bb the advisory said.<\/p>\n<p>Two of those models, the 750-882 and the 750-885\/0xx-xxx, are absent from both the advisory&#8217;s mitigation section and its remediation table, leaving their fix status unstated.<\/p>\n<p>Siemens, which maintains Nucleus, states in <a href=\"https:\/\/cert-portal.siemens.com\/productcert\/html\/ssa-044112.html\" target=\"_blank\">its Nucleus advisory<\/a> that no remediation is planned for Nucleus NET across all versions, and that Nucleus ReadyStart V3 releases from V2013.08.1 onward already fix CVE-2021-31886.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The flaw was one of 13 disclosed in November 2021 as NUCLEUS:13 by Forescout and Medigate. In its earlier research on chaining PLC exploits, Forescout concluded that the issues discussed \u00abshould likely not be near the top of your priority list,\u00bb and said AI advances should make organizations reconsider that risk calculus.<\/p>\n<p>The research follows a <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa26-231a\" target=\"_blank\">joint advisory issued August 19<\/a> by the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency, which warned of an active threat to internet-exposed Siemens S7 Series PLCs from AI-generated exploitation scripts.<\/p>\n<p>The agencies assess that the activity is likely intended for persistent reconnaissance and capability development and have stopped short of attribution.<\/p>\n<p>Separately, the FBI and the EPA <a href=\"https:\/\/www.fbi.gov\/investigate\/cyber\/alerts\/2026\/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions\" target=\"_blank\">reported attacks on water utilities<\/a> in at least seven states since July 27, some of which degraded operations. Those actors changed IP addresses and passwords on internet-facing Rockwell Automation MicroLogix controllers, in attacks that needed no exploit.<\/p>\n<p>\u00abUsing AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools,\u00bb the authoring agencies said in the joint advisory.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Forescout Research &#8211; Vedere Labs said it used Anthropic&#8217;s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2641,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[9,120,111,2691,726,1040,316,605],"class_list":["post-2640","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-claude","tag-exploit","tag-model","tag-plc","tag-port","tag-preauth","tag-rce","tag-researchers"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2640","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2640"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2640\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2641"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2640"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2640"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2640"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}