Claude Code Exploit Ported an Older Vulnerability Between WAGO PLCs in a Lab

According to two reports, researchers used Claude Code to adapt an existing exploit for the older CVE-2021-31886 vulnerability from one WAGO PLC to a related model. This was not a new vulnerability or a confirmed attack in operation.

Claude Code exploit, according to reports by SecurityWeek and The Hacker News, enabled researchers to port an existing laboratory exploit for CVE-2021-31886 from a WAGO 750-852 PLC to a physical WAGO 750-831 device. On the target PLC, they achieved controlled code execution under human supervision. The demonstration does not represent a new vulnerability or confirm real-world exploitation in industrial operations.

The CVE-2021-31886 vulnerability affects the Nucleus FTP server. An unchecked USER command length can lead to a stack overflow and subsequently to denial of service or remote code execution. CERT@VDE previously listed WAGO models 750-831 and 750-852 among the affected devices in specified older firmware versions.

Claude Code exploit was based on an older CVE

This was not an attack developed for a previously unknown vulnerability. According to available information, the researchers started with an exploit used in earlier research on the WAGO 750-852 model and adapted it to the related 750-831 PLC. Forescout’s original NUCLEUS:13 research documented the technical nature of the vulnerability in the Nucleus TCP/IP stack and earlier testing on a WAGO device.

SecurityWeek reports that the experiment’s final phase lasted more than eight hours and that API costs exceeded $500. The researchers did not proceed without intervention: a human continuously reviewed the results. Secondary reports provide details about the tool used, costs, and process, citing statements from Forescout; however, no independently verifiable first-party report on this specific experiment was available.

The test did not end with a functional implant

According to The Hacker News, the demonstrated capability ended with sending network packets and controlled code execution. During a subsequent attempt to create a C2 implant, the researchers reportedly damaged the tested PLC by writing to an area mapped to flash memory. The device was permanently damaged.

This result is an important limitation when interpreting the experiment. It does not mean that the tool can autonomously and reliably develop usable exploits for any industrial control systems. In the described case, an existing laboratory exploit was adapted between related models, and expert guidance was required.

The risk primarily concerns older and accessible devices

PLCs control physical industrial processes, so even laboratory code capable of remote code execution has operational significance. The device damage during testing also shows that imprecise actions against a control system can have consequences even without successfully creating a persistent malicious mechanism.

Operators of older WAGO 750-831 and 750-852 PLCs should verify whether the FTP service is exposed on the network and review network segmentation. The current patch status for all affected legacy devices was not independently confirmed within the available materials. The older CERT@VDE advisory describes the affected firmware; however, this case cannot be presented as a new patch.

Further developments will show whether Forescout publishes a technical report with a reproducible methodology, whether WAGO or CERT@VDE issue new statements on mitigations and firmware, and, above all, whether credible evidence emerges of real-world exploitation of CVE-2021-31886 or an exploit ported in this way.

Sources

  • SecurityWeek – Reports the outcome of the laboratory exploit port, the need for human supervision, time and API costs, and damage to the tested PLC.
  • The Hacker News – Adds the target WAGO 750-831 model, the connection to CVE-2021-31886, and states that the demonstrated capability ended with sending network packets.
  • CERT@VDE – Confirms that CVE-2021-31886 is a critical vulnerability in the Nucleus FTP server and that affected WAGO products include 750-831 and 750-852 with specified older firmware.
  • Forescout – Documents the original NUCLEUS:13 research, the technical nature of CVE-2021-31886, and earlier testing on WAGO 750-852.

Verified and updated: 09/02/2026 11:28

Sharing