logo

Claude AI Develops Working RCE Exploit Against WAGO PLC With Researcher Assistance

ID: 6988a582-2e91-51c1-bd41-cfdd8ded1981

STIX ID: report--6988a582-2e91-51c1-bd41-cfdd8ded1981

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-09-02

Date Updated: 2026-09-11

Author: Divya

...
...

Researchers demonstrated that a large language model (Anthropic’s Claude) can assist in porting a remote code execution exploit for CVE-2021-31886 against WAGO PLCs by analyzing firmware, identifying memory/layout details, and generating ARM shellcode; the AI required extensive human guidance, incurred roughly $536 in API costs for the final development phase, and produced payloads that caused the PLC to send ICMP/UDP beacons and in one case permanently brick a device. The report highlights both the promise of AI to lower adaptation effort for embedded targets and current limitations, and recommends minimizing OT exposure, monitoring anomalous FTP activity, and rehearsing incident response for AI-assisted attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.