Claude Ported a WAGO PLC Exploit Across Models

Forescout’s Vedere Labs said Claude helped port a working remote code execution exploit from the WAGO 750-852 to the related 750-831, but only after more than eight hours of work, heavy human supervision, and over $500 in API usage. The exploit was originally tied to CVE-2021-31886 in the WAGO Nucleus FTP server. The model first used firmware analysis, Ghidra, and a live device to confirm the flaw, then had to be steered away from false leads until it figured out why injected code was being wiped before execution. Once that obstacle was solved, it produced working payloads quickly, showing how much the hard part is getting to first execution and how fast adaptation can move after that. For OT teams, the point is not a new WAGO bug; it is that a known exploit can be reworked across sibling PLCs with less manual reverse engineering than before. If your control estate uses related device families, one understood model can shorten the path to others.

Part of the PlainSec briefing for 2026-09-01

Every edition of this story: Claude Ported a WAGO PLC Exploit Across Models

Sources