TechNewsReel
Live

AI Automates Porting of RCE Exploit Across Industrial PLC Models

Forescout's Vedere Labs demonstrated how Claude LLM can adapt critical infrastructure exploits to new hardware targets, lowering the barrier for attacks.

TechNewsReel Newsroom · September 2, 2026

Security researchers have demonstrated that large language models can be used to adapt complex exploits for industrial hardware, significantly lowering the technical barrier for attacking critical infrastructure. Forescout's Vedere Labs successfully used Anthropic's Claude LLM to port a pre-authentication remote code execution (RCE) exploit between different WAGO programmable logic controller (PLC) models.

The researchers targeted CVE-2021-31886, a known stack-based buffer overflow vulnerability found in the Nucleus FTP server's handling of the USER command. By leveraging Claude, the team ported a working exploit from the WAGO 750-852 model to the 750-831 model. This process culminated in the successful execution of attacker-supplied ARM shellcode on live hardware, confirming that the AI-assisted port was fully functional.

The Technical Challenge of Porting

Programmable Logic Controllers are the backbone of industrial control systems (ICS), managing everything from factory assembly lines to power grids. Historically, porting an exploit from one hardware model to another has been a labor-intensive process. It typically requires deep manual reverse engineering to account for differences in memory layouts, register usage, and specific architectural nuances between device versions.

In this instance, the vulnerability exists within the Nucleus FTP server, a third-party component embedded in various industrial devices. While the underlying flaw remained the same across models, the specific memory addresses and offsets required to trigger the overflow and execute shellcode differed, necessitating the porting process that the researchers automated using the LLM.

Implications for Industrial Security

This research signals a shift in the threat landscape by demonstrating that LLMs can automate the most tedious aspects of exploit development. By reducing the need for expert-level manual reverse engineering, AI allows attackers to scale their capabilities more rapidly. This increases the risk to industrial environments that rely on legacy hardware or fail to apply patches to embedded components like the Nucleus FTP server.

As LLMs become more proficient at analyzing binary structures and assembly code, the window between the discovery of a vulnerability in one device and the creation of a working exploit for an entire product line may shrink considerably.

Future Outlook

While the research highlights a vulnerability in the software, it more broadly exposes a vulnerability in the current security paradigm. The ability to rapidly adapt RCE exploits means that "security through obscurity" or relying on the difficulty of hardware-specific porting is no longer a viable defense.

Industry observers will now be watching to see if LLM providers implement stricter guardrails against the generation of exploit code for ICS hardware, and whether industrial vendors can accelerate the patching of embedded third-party libraries to mitigate these AI-driven threats.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.