Skip to finding
important · Firmware — PLC

The known Nucleus FTP overflow now executes ARM shellcode on a physical WAGO 750-831.

Affects

WAGO 750-831 programmable logic controllers used in industrial automation, running the embedded Nucleus TCP/IP stack.

The target-specific sequence uses an oversized pre-authentication USER payload and a CWD request without a CRLF so normal FTP processing does not erase the shellcode.

Detail and 2 sources

Two payloads emitted attacker-selected ICMP and UDP traffic from the physical controller, and the original advisory lists the 750-831 family as affected.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 3, 2026