Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command
Why This Matters
The evidence matters to defenders using Claude because it could let an attacker run code in affected environments.
Recommended Action
Confirm whether WAGO is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
CVE: CVE-2021-31886
Affected