AI
Published 2026-09-02
Verified 2026-09-19

Forescout: Claude-assisted port of WAGO PLC pre-auth RCE (CVE-2021-31886) to 750-831

Forescout Vedere Labs (covered by The Hacker News on 2 September 2026) reports researcher-guided use of Anthropic Claude to port a working pre-authentication RCE exploit for CVE-2021-31886 (Nucleus FTP USER-command stack buffer overflow, Siemens CVSS 9.8, TCP/21) from a WAGO 750-852 to a WAGO 750-831 on firmware V01.04.16, executing ARM shellcode on live hardware. The port needed sustained human steering; the final RCE stage cost about US$535.74 in API usage over roughly 8.5 hours. CERT@VDE advisory VDE-2021-050 says no updates are available for affected WAGO controllers and advises disabling/blocking FTP on port 21, segmentation, and traffic monitoring. A later session that tried to build a C2 implant bricked the PLC by writing flash-mapped memory. Forescout notes a skilled researcher might have finished the initial port without AI faster and cheaper. Old CVE, new AI-assisted exploit-port demonstration — useful for OT change-control and agentic-coding risk discussions.

Product
WAGO 750-831 / 750-852 PLC (Nucleus FTP); Anthropic Claude (research assist)
Versions
Demonstrated on WAGO 750-831 firmware V01.04.16; CVE-2021-31886 unpatched per CERT@VDE
CVSS
CVE-2021-31886 Siemens CVSS 9.8 (vendor-assigned on original advisory)
Exploited in Australia?
unknown
Patch to
Disable/block FTP :21 on affected WAGO; segment OT; no firmware fix per CERT@VDE

Primary: Forescout Vedere Labs blog (Claude / WAGO PLC) · Vendor: CERT@VDE VDE-2021-050 (WAGO / CVE-2021-31886) · CVE: CVE-2021-31886 · The Hacker News (2 Sep 2026)

ai ot ics