Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Sep 2, 2026

Forescout Research – Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware.

The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server’s handling of the USER command

Get Free Report & Network Analysis

Please check your email for the free report.