Claude moves a pre-auth PLC exploit to new hardware for $536

Forescout guided Claude through a $536 exploit port between WAGO controllers, then watched a follow-up session brick the test PLC.

CSBadmin
2 Min Read

Forescout’s Vedere Labs research unit used Anthropic’s Claude to carry a working pre-authentication remote code execution exploit from one WAGO programmable logic controller to another, running attacker-supplied ARM shellcode on live hardware.

The ported exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server’s handling of the USER command, rated CVSS 9.8 and reachable on TCP port 21 before authentication. The team moved the attack from a WAGO 750-852 to a 750-831 running firmware V01.04.16, guiding Claude Code through interactive sessions that had terminal access, the Ghidra reverse-engineering tool, and the physical controller as a live target. The final RCE stage cost $535.74 in API fees over an 8-hour-32-minute session, with researchers steering the model at each step.

CERT@VDE says no updates are available for the affected controllers and recommends blocking FTP on port 21, enforcing segmentation, and monitoring for anomalies. A later session in which the model tried to extend the exploit into a command-and-control implant wrote to a flash-mapped memory region and permanently bricked the PLC.

The exercise follows an August 19 joint advisory from the NSA, CISA, the FBI, the Department of Energy, and the EPA warning that AI-generated scripts are hunting internet-exposed Siemens S7 PLCs. Forescout’s takeaway: the more immediate risk may be authorized agents taking the wrong action on physical systems where failure carries real operational consequences.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.