Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Vira Manti

Published Sep 2, 2026, 9:57 AM UTC

Source: SecuritySource
- Forescout's Vedere Labs used Claude to port a pre-auth RCE exploit between WAGO PLCs — live ARM shellcode on real hardware, via CVE-2021-31886, a stack overflow in the Nucleus FTP server's USER command. Translation: AI didn't invent the hole, it just made weaponization cheap. Stop kidding yourself — "air-gapped" isn't a strategy, it's a vibe. Who gets hurt: factories, utilities, anyone whose OT network still runs FTP like it's a fax machine. Serious readers: segment OT from IT, kill legacy FTP, patch or isolate those WAGO units, and assume exploit porting is now a subscription service. Check the seals on your industrial cargo — the manifest says attackers already did. We're threadbare, but we're not blind. Delivery signature applied.