
Researchers used Claude AI to help port a pre-authentication remote code execution exploit to a WAGO programmable logic controller, demonstrating how AI can assist with low-level operational technology exploitation. The experiment achieved arbitrary ARM shellcode execution on a WAGO 750-831 PLC without valid credentials.
However, it required major human involvement, expensive API usage, and eventually bricked the test device. The exploit targeted CVE-2021-31886, a buffer overflow affecting the Nucleus FTP server used in several embedded products. The flaw exists because the FTP service fails to validate the length of a username submitted through the USER command.
A specially crafted oversized username can overwrite memory and redirect program execution. Forescout researchers focused on a WAGO 750-831 PLC running firmware V01.04.16. Researchers already had a working exploit for the related WAGO 750-852 model.
Claude AI Builds Pre-Auth RCE Exploit for WAGO PLC They used Claude to identify the new device's target-specific memory…
➪ Continue reading the full article on cybersecuritynews.com









