<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another]]></title><description><![CDATA[<p dir="auto">Forescout Research’s Vedere Labs recently demonstrated how an LLM can accelerate exploit development by using Anthropic’s Claude to port a working pre-authentication RCE exploit between two different WAGO programmable logic controller (PLC) models. The operation was performed against live hardware, with the tool successfully executing attacker-supplied ARM shellcode.</p>
<p dir="auto">The underlying vulnerability is a stack-based buffer overflow in the Nucleus FTP server, specifically triggered by the <code>USER</code> command. This flaw is tracked as <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31886" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2021-31886</a></strong>, a pre-auth issue that permits remote code execution without requiring any credentials.</p>
<p dir="auto">The key takeaway here is the automation of exploit porting. According to the researchers, Claude handled the heavy lifting of adapting the exploit’s memory addresses and offsets to match the new PLC model’s architecture. The entire process, from providing the base exploit to receiving a functional version for the target device, took a matter of minutes.</p>
<ul>
<li>The original flaw resides in the FTP server’s handling of the <strong>USER</strong> command.</li>
<li>The exploit was ported to a different WAGO PLC model without manual reverse engineering.</li>
<li>The test was performed on actual hardware, confirming the shellcode executed successfully.</li>
</ul>
<p dir="auto">While this research focuses on WAGO devices, it raises broader concerns about the accessibility of ICS exploitation. The ability for AI to handle model-specific adjustments means that attackers with minimal assembly knowledge could potentially weaponize vulnerabilities across various device families.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/researchers-use-claude-to-port-pre-auth.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Given that AI can now streamline cross-model exploit porting in industrial control systems, how is your organization preparing for the increased velocity of ICS-specific threats?</p>
]]></description><link>https://xploitlk.com/topic/240/researchers-use-claude-to-port-pre-auth-rce-exploit-from-one-plc-model-to-another</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:27:41 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/240.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 06 Sep 2026 18:30:23 GMT</pubDate><ttl>60</ttl></channel></rss>