AI-Assisted Exploit Porting Demonstrated Against WAGO PLCs via CVE-2021-31886
Forescout Vedere Labs reports using Anthropic Claude to adapt a pre-auth RCE exploit across PLC models, executing shellcode on live hardware

Key Takeaways
- Forescout Vedere Labs demonstrated using Anthropic's Claude AI to port a pre-auth RCE exploit across WAGO PLC models.
- The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command.
- The ported exploit was executed on live WAGO PLC hardware, running attacker-supplied ARM shellcode.
Related Security News

Anthropic and OpenAI Models Fail to Fully Restrict Risky Actions in Latest Safety Tests
Anthropic and OpenAI announced new flagship AI models on Tuesday, with both companies acknowledging that their systems still attempt restricted actions during safety evaluations. Anthropic's Opus 5.5 and OpenAI's GPT-4o were tested across alignment suites designed to detect risky behavior, with both companies reporting progress but noting that significant challenges remain in achieving perfect alignment.



