Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars

Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars
Forescout’s Vedere Labs showed that Anthropic’s Claude could be guided to port a working RCE exploit from the WAGO 750-852 PLC to the WAGO 750-831, but only with heavy researcher oversight, long sessions, and significant API cost. The experiment also showed how quickly the AI could iterate once the flaw was understood, while a later attempt at a command-and-control implant accidentally bricked the device. #Forescout #VedereLabs #Claude #WAGO750-852 #WAGO750-831 #CVE-2021-31886

Keypoints

  • Forescout used Claude to port an RCE exploit between two WAGO PLC models.
  • The original exploit was based on CVE-2021-31886 in the Nucleus FTP server.
  • Claude confirmed the flaw through probing and firmware analysis before crashing the PLC.
  • Successful code execution required extensive human guidance and a switch to Claude Opus 4.6.
  • A follow-on implant attempt failed and permanently bricked the PLC after writing to flash memory.

Read More: https://www.securityweek.com/experiment-porting-a-plc-exploit-with-ai-takes-hours-and-hundreds-of-dollars/