Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Summary
Researchers used Anthropic's Claude AI to adapt a working exploit for CVE-2021-31886, a stack-based buffer overflow (a type of memory safety flaw where attackers overflow a fixed-size buffer to overwrite adjacent memory) in WAGO programmable logic controllers (PLCs, which are computers that control industrial equipment), allowing them to execute attacker-supplied code on a different PLC model without needing to authenticate first. The vulnerability has a CVSS score of 9.8 (a 0-10 rating of how severe a vulnerability is) and is exploitable over network port 21.
Solution / Mitigation
CERT@VDE advises owners to: (1) disable or block FTP on port 21, (2) enforce segmentation controls, and (3) monitor network traffic for anomalies. The advisory notes that no firmware updates are available for the affected WAGO controllers.
Classification
Affected Vendors
Related Issues
Original source: https://thehackernews.com/2026/09/researchers-use-claude-to-port-pre-auth.html
First tracked: September 2, 2026 at 08:00 AM
Classified by LLM (prompt v3) · confidence: 75%