Users and operators of WAGO PLCs with Nucleus FTP server should apply vendor-supplied patches or mitigations for CVE-2021-31886. Network segmentation should be used to limit exposure of FTP services in industrial environments. Monitoring for unusual FTP activity is recommended.
Quick answers
What is CVE-2021-31886?
Users and operators of WAGO PLCs with Nucleus FTP server should apply vendor-supplied patches or mitigations for CVE-2021-31886. Network segmentation should be used to limit exposure of FTP services in industrial environments. Monitoring for unusual FTP activity is recommended.
How severe is CVE-2021-31886?
high, CVSS 9.8
Is CVE-2021-31886 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2021-31886 be mitigated?
Users and operators of WAGO PLCs with Nucleus FTP server should apply vendor-supplied patches or mitigations for CVE-2021-31886. Network segmentation should be used to limit exposure of FTP services in industrial environments. Monitoring for unusual FTP activity is recommended.
CVSS
9.8
Vendor
WAGO
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
Nucleus FTP Server, WAGO PLC
Mitigation
Users and operators of WAGO PLCs with Nucleus FTP server should apply vendor-supplied patches or mitigations for CVE-2021-31886. Network segmentation should be used to limit exposure of FTP services in industrial environments. Monitoring for unusual FTP activity is recommended.
Researchers from Forescout Vedere Labs demonstrated the use of Anthropic's Claude AI to port a working pre-authentication remote code execution exploit from one WAGO programmable logic controller model to another. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command. The ported exploit was executed on live WAGO PLC hardware, executing attacker-supplied ARM shellcode. The demonstration highlights the potential for AI to accelerate exploit development and porting across industrial control system platforms.