Study: Anthropic's Claude Ports Pre-Authentication RCE Exploit Across PLC Models

Study: Anthropic's Claude Ports Pre-Authentication RCE Exploit Across PLC Models

Security researchers demonstrate that Anthropic's Claude can adapt a pre-authentication remote code execution exploit from one programmable logic controller to another, lowering the skill barrier for attack code reuse.

Security researchers have demonstrated that Anthropic's Claude artificial intelligence model can be used to port a pre-authentication remote code execution (RCE) exploit from one programmable logic controller (PLC) model to another. A PLC is a small industrial computer that controls physical equipment such as assembly lines, heating and cooling systems, and water pumps. Pre-authentication RCE means an attacker can run their own commands on a device over a network without first providing a password. Porting an exploit means taking attack code that works against one device and modifying it so that it also works against a different but similar device.

This finding matters because PLCs are often used in critical infrastructure and building management. Historically, adapting an exploit from one PLC model to another required a human attacker with deep knowledge of the target hardware and its memory layout. The demonstration suggests that large language models like Claude can reduce the time and expertise needed to adapt such attacks. This does not mean the AI discovered a new vulnerability; rather, it helped modify an existing exploit so it could target another device. The same approach could be used by defenders to quickly produce test cases for security patches across many device variants.

The headline does not specify which PLC models were involved or how successful the port was, but the fact that a public report describes this technique is enough to raise concern. Attackers who find one pre-auth RCE in a popular PLC family may now be able to produce working exploits for related models with far less effort. For organizations that run industrial equipment, the window between vulnerability disclosure and active exploitation may shrink significantly.

Website owners and IT teams should pay attention because the same principle applies to any network-connected device, not just industrial controllers. Many data centers and server rooms depend on PLCs for cooling, power monitoring, and physical access control. If one of those controllers is reachable from the internet and has a pre-auth RCE, an attacker could disrupt the environment that hosts websites and cloud services. Even if a website itself is fully patched, a compromise of building systems can cause downtime or data loss.

For organizations concerned about this shift, AEU Group's AEU-I service provides security-first IT and infrastructure consulting that can help inventory internet-facing devices, apply network segmentation, and verify that industrial controllers are not exposed to pre-auth RCE vulnerabilities. The broader lesson is that every connected device on a network is a potential entry point, and AI-assisted exploit adaptation makes fast patching more important than ever.

How to Protect Yourself

  1. Regularly update the firmware on all internet-connected equipment, including any smart building devices or industrial controllers you may manage, to close known security holes.
  2. Keep industrial or building management devices on a separate network that is not directly reachable from the public internet, and block incoming connections to them.
  3. Change default usernames and passwords on every network-connected device and disable remote access features you do not use.
  4. Ask your IT provider or hosting company to monitor for unusual traffic to your internal devices, especially any attempts to reach control systems.
  5. Before buying any internet-connected equipment, check whether the vendor provides regular security updates and a way to disable remote access.

Related AEU services

  • AEU-I IT and security consulting