Research · curated 2 Sep 2026

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Coverage timeline

discovered forescout.com primary 2 Sep 2026thehackernews.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

Forescout's experiment shows that frontier LLMs can meaningfully assist in porting real pre-auth RCE exploits to new industrial control hardware, lowering the bar for adapting ICS attacks even though the process still demands expert steering.

Forescout Research (Vedere Labs) demonstrated using Anthropic's Claude to port a working pre-authentication RCE exploit for CVE-2021-31886 (a CVSS 9.8 stack-based buffer overflow in the Nucleus FTP server) from one WAGO PLC model to another, executing attacker-supplied ARM shellcode on live hardware. The effort required sustained researcher steering and consumed $535.74 in API usage over an 8.5-hour session; a later attempt to build a C2 implant permanently bricked the PLC.