Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-02 ยท updated: 2026-09-02 ยท tags: [cve, buffer-overflow, ics, code-execution, energy] ยท confidence: high ยท severity: critical ยท affected_sectors: [energy, manufacturing] ยท au_impact: true

CVE-2021-31886

Summary

CVE-2021-31886 (CVSS 9.8) is a stack-based buffer overflow in the Nucleus FTP server's USER command handling on certain WAGO programmable logic controllers (PLCs). It is reachable pre-authentication over TCP port 21 and allows remote code execution โ€” demonstrated on live hardware by Forescout's Vedere Labs using an AI-assisted port of the exploit.

Details

The overflow was exploited pre-authentication over TCP port 21 to execute attacker-supplied ARM shellcode on live WAGO PLC hardware. Forescout's Vedere Labs ported a working exploit for one WAGO PLC model to another using Anthropic's Claude over an 8.5-hour, US$535.74-API-usage session; a later attempt to extend the exploit into a C2 implant wrote to a flash-mapped region and permanently bricked the PLC. CERT@VDE advises that no updates are available for the affected WAGO controllers.

Remediation

Because no patch exists for the affected controllers, CERT@VDE advises disabling or blocking FTP on port 21, enforcing network segmentation of PLC/OT segments, and monitoring for anomalies. This is a standing OT exposure rather than a fixable CVE.

Source