Research · curated 2 Sep 2026
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
First reported forescout.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Forescout's experiment shows that frontier LLMs can meaningfully assist in porting real pre-auth RCE exploits to new industrial control hardware, lowering the bar for adapting ICS attacks even though the process still demands expert steering.
Forescout Research (Vedere Labs) demonstrated using Anthropic's Claude to port a working pre-authentication RCE exploit for CVE-2021-31886 (a CVSS 9.8 stack-based buffer overflow in the Nucleus FTP server) from one WAGO PLC model to another, executing attacker-supplied ARM shellcode on live hardware. The effort required sustained researcher steering and consumed $535.74 in API usage over an 8.5-hour session; a later attempt to build a C2 implant permanently bricked the PLC.