PoC public WAGO PLCs ai-ml Nucleus RTOS Siemens rce
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
CVE Tools coverage
Forescout Research utilized Anthropic's Claude to adapt a pre-authentication remote code execution exploit from one Siemens-made WAGO Programmable Logic Controller model to another, successfully executing shellcode on the target hardware. The attack leverages CVE-2021-31886, a critical stack-based buffer overflow in the Nucleus RTOS FTP server that allows unauthenticated attackers to inject malicious code via TCP port 21. As no software update is currently available for the affected WAGO devices, CERT@VDE recommends disabling the FTP service, implementing network segmentation, and closely monitoring traffic for suspicious activity.