CVE Tools

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

The Hacker NewsBy The Hacker News

PoC publicWAGO PLCsNucleus RTOS

Our summary

Forescout Research utilized Anthropic's Claude to adapt a pre-authentication remote code execution exploit from one Siemens-made WAGO Programmable Logic Controller model to another, successfully executing shellcode on the target hardware. The attack leverages CVE-2021-31886, a critical stack-based buffer overflow in the Nucleus RTOS FTP server that allows unauthenticated attackers to inject malicious code via TCP port 21. As no software update is currently available for the affected WAGO devices, CERT@VDE recommends disabling the FTP service, implementing network segmentation, and closely monitoring traffic for suspicious activity.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store