Forescout Vedere Labs used Anthropic’s Claude Code to adapt a known remote-code-execution exploit from a WAGO 750-852 programmable logic controller (PLC) to the related WAGO 750-831. The exploit abuses CVE-2021-31886, a pre-authentication buffer overflow in the Nucleus FTP server that enables unauthenticated execution of arbitrary ARM shellcode. With terminal access, Ghidra, reference files, and a physical PLC, researchers confirmed the flaw and produced working payloads, although human researchers had to resolve false leads and supply reverse-engineering context.
The initial exploit-porting effort took eight hours and 32 minutes and cost $535.74 in API usage, indicating AI remained less efficient than a skilled human expert for this task. After code execution was achieved, however, the model created working network payloads within minutes; a later attempt to create a command-and-control implant bricked the test PLC after writing to flash-mapped memory. Researchers warned that improving models and faster post-breakthrough iteration could lower the expertise and cost needed to adapt embedded-system exploits, raising operational-technology and critical-infrastructure risk.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
WAGO reported that multiple controller models are affected by NUCLEUS TCP/IP vulnerabilities that could let an attacker with device access manipulate or disrupt equipment. It listed models affected by all referenced flaws and a second group affected only by CVE-2021-31344, CVE-2021-31346, and CVE-2021-31890, while stating that WAGO devices are not affected by CVE-2021-31885.
Siemens published security advisory SSA-044112 addressing multiple vulnerabilities in the TCP/IP stack of Nucleus RTOS (NUCLEUS:13).
In a separate effort to extend the RCE into a command-and-control implant, Claude tested increasingly complex payloads. One payload wrote to flash-mapped memory and permanently bricked the physical WAGO PLC target.
After researcher guidance and changes to preserve injected code that was being erased before execution, Claude generated working payloads for the WAGO 750-831. The RCE-development stage took more than eight hours, including an eight-hour-and-32-minute reported exercise costing $535.74 in API usage.
Researchers found that normal FTP processing cleared the buffer containing injected shellcode after the oversized USER command. They preserved the buffer by following USER with CWD without a CRLF terminator, enabling arbitrary ARM shellcode execution on the WAGO 750-831.
Forescout Vedere Labs used Claude Code, reverse-engineering tools, and a live WAGO 750-831 PLC to verify that CVE-2021-31886 could be adapted from the WAGO 750-852. An initial payload crashed the PLC, confirming the vulnerability but not delivering controlled execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourceitsecurityguru.org
Open sourcesecurityweek.com
Open sourceforescout.com
Open sourceitpro.com
Open sourcecertvde.com
Open sourcecert-portal.siemens.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.