CVE-2021-31886
Summary
CVE-2021-31886 (CVSS 9.8) is a stack-based buffer overflow in the Nucleus FTP server's USER command handling on certain WAGO programmable logic controllers (PLCs). It is reachable pre-authentication over TCP port 21 and allows remote code execution โ demonstrated on live hardware by Forescout's Vedere Labs using an AI-assisted port of the exploit.
Details
The overflow was exploited pre-authentication over TCP port 21 to execute attacker-supplied ARM shellcode on live WAGO PLC hardware. Forescout's Vedere Labs ported a working exploit for one WAGO PLC model to another using Anthropic's Claude over an 8.5-hour, US$535.74-API-usage session; a later attempt to extend the exploit into a C2 implant wrote to a flash-mapped region and permanently bricked the PLC. CERT@VDE advises that no updates are available for the affected WAGO controllers.
Remediation
Because no patch exists for the affected controllers, CERT@VDE advises disabling or blocking FTP on port 21, enforcing network segmentation of PLC/OT segments, and monitoring for anomalies. This is a standing OT exposure rather than a fixable CVE.