AI-Powered PLC Exploits: Forescout Reveals the Cost of Automation
- Forescout's Vedere Labs successfully ported a remote code execution (RCE) exploit between WAGO PLC models using Claude AI.
- The process required 8 hours and 32 minutes of work and cost 5.74 in API fees.
- AI alone could not complete the task; extensive human oversight and reverse-engineering tools were essential.
- An attempt to create a C2 implant resulted in the permanent bricking of the physical hardware.

The intersection of Large Language Models (LLMs) and Industrial Control Systems (ICS) has long been a point of theoretical concern for cybersecurity experts. Recent experiments by researchers at Forescout's Vedere Labs have moved this conversation from theory to empirical data. By utilizing Anthropic's Claude, the team attempted to port a known remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) model to another, revealing both the potential and the current limitations of AI-driven offensive security.
The mechanics of the AI experiment
The research began with a documented vulnerability, CVE-2021-31886, which involves a pre-authentication buffer overflow in the Nucleus FTP server. This specific flaw allows an unauthenticated attacker to execute arbitrary ARM shellcode on a targeted PLC. While the exploit was already functional for the WAGO 750-852 model, the researchers wanted to see if Claude could adapt this attack for the WAGO 750-831.
To achieve this, the researchers provided the AI with a comprehensive toolkit. Claude Code was given access to a terminal, reference files, and the physical target device. Crucially, the AI was integrated with Ghidra, a sophisticated reverse-engineering tool. The workflow involved a combination of live probing and static firmware analysis to confirm that the vulnerability existed in the new model. While the AI managed to generate a payload that crashed the PLC—confirming the flaw—this initial success represented only the simplest part of the operation.
Why human oversight remains non-negotiable
The narrative that AI can autonomously dismantle industrial security is challenged by the actual resource expenditure of this experiment. Achieving a full RCE was not a matter of a single prompt; it required 8 hours and 32 minutes of dedicated effort and a financial investment of 5.74 in API costs. The researchers had to pivot between different versions of the AI, utilizing both Claude Sonnet 4.6 and Claude Opus 4.6 to overcome technical hurdles.
The process was characterized by a constant loop of trial and error. Humans were required to correct the AI when it reached dead ends, provide essential disassembly context from Ghidra, and prompt the model when firmware details remained uncertain. A significant roadblock occurred when standard FTP processing began zeroing out the shellcode, a nuance that required human intervention to identify and resolve. This suggests that while AI can accelerate the drafting of exploits, the deep architectural knowledge of closed-source embedded systems still resides with the human expert.
The risk of physical hardware failure
One of the most striking findings of the Vedere Labs study is the potential for AI to cause unintended physical destruction. After successfully achieving RCE, the researchers attempted to push the experiment further by developing a full command-and-control (C2) implant. This stage proved far more volatile than the initial exploit porting.
The experiment demonstrated that AI-driven exploit development can lead to catastrophic errors, as an incorrect write to flash memory during the C2 implant expansion permanently bricked the PLC.
This outcome highlights a critical gap in AI's current capability: a lack of inherent understanding of the physical consequences of its code. In a real-world industrial environment, such an error would not merely be a failed experiment but could result in significant operational downtime or the destruction of critical infrastructure components.
Analyzing the technical workflow
The methodology employed by Forescout provides a blueprint for how modern threat actors might integrate AI into their pipelines. The process was not linear but iterative, relying on the AI to handle the repetitive aspects of code generation and analysis while the human acted as the strategic lead.
The researchers utilized a specific sequence to move from a crash to a controllable exploit. First, they used the AI to analyze the existing WAGO 750-852 exploit and the 750-831 firmware (V01.04.16). Once the buffer overflow was confirmed via a Denial of Service (DoS) attack, the focus shifted to transitioning that crash into executable code. The final output was a set of UDP payloads capable of delivering an ICMP echo payload and the string 'PWNED', proving that the AI-assisted process could indeed achieve remote code execution.
Evaluating the cost of AI-driven attacks
For business leaders and CISOs, the most relevant data point may be the cost-benefit analysis of using AI for such attacks. The expenditure of over 0 in API fees for a single exploit port, combined with nearly nine hours of expert labor, suggests that AI is currently a force multiplier rather than a replacement for skilled hackers. However, the porting process demonstrates that the barrier to entry is lowering.
The ability to use AI to bridge the gap between two different hardware models reduces the time a researcher must spend manually analyzing memory layouts and processing paths. As LLMs become more efficient and API costs potentially decrease, the window of time between the discovery of a vulnerability in one device and its adaptation to another will likely shrink.
Global implications for industrial enterprises
For companies operating in the USA, UK, and other global markets, this research underscores a shift in the threat landscape for Operational Technology (OT). Industrial environments often rely on legacy hardware that is difficult to patch and lacks modern debugging tools. The fact that AI can now assist in porting exploits across different PLC models means that a vulnerability found in one piece of equipment could more quickly threaten an entire fleet of diverse hardware.
In the United States and the United Kingdom, where critical infrastructure protection is a national security priority, this emphasizes the need for a defense-in-depth strategy. Relying solely on the obscurity of closed-source firmware is no longer a viable security posture. Enterprises should focus on network segmentation and anomaly detection to identify the 'live probing' and 'static analysis' phases of an attack before a payload is ever delivered.
From a regulatory perspective, while the EU AI Act focuses heavily on the classification of AI risk, US and UK firms should look toward updated ICS security frameworks. The ability of AI to automate parts of the exploit chain means that vulnerability management must move faster than the traditional quarterly or annual audit cycle. The Forescout experiment proves that while the AI is not yet a 'push-button' weapon, it is a highly capable assistant that can significantly compress the development cycle of a targeted cyber-physical attack.
FAQ
Did the AI autonomously create the exploit?
No. The AI required constant human oversight, correction of hypotheses, and the provision of disassembly context to succeed.
Which AI models were used in the Forescout experiment?
The researchers used Claude Code, specifically utilizing Claude Sonnet 4.6 and Claude Opus 4.6.
What happened when the researchers tried to create a C2 implant?
The AI performed an incorrect write to the flash memory, which permanently bricked the physical WAGO PLC device.
How much did the AI-assisted exploit porting cost?
The process took 8 hours and 32 minutes and cost 5.74 in API usage fees.
Sources: Securityweek, Dev, Letsdatascience ·
Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.
Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.
oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email

