Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Read original article ↗AI Summary
Researchers from Forescout's Vedere Labs used Anthropic's Claude to successfully port a pre-authentication remote code execution (RCE) exploit from one WAGO PLC model (750-852) to another (750-831), exploiting CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server. The exploit was adapted to bypass buffer zeroing by modifying FTP command sequences (USER and CWD) and omitting CRLF terminators, enabling execution of attacker-supplied ARM shellcode. The attack achieved code execution on live hardware, demonstrated via ICMP and UDP 'PWNED' payloads, though a later attempt to create a C2 implant bricked the device. No patches are available for affected WAGO devices, which run on Nucleus V1 RTOS.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.