Tec Nikan
فارسی
Talk to us
All news

Porting a PLC Exploit With AI Took Eight Hours and $536

Forescout put a number on a question every plant security lead is being asked. The AI-assisted path worked, needed constant expert help, and permanently bricked the controller at the last stage.

OT securityPLCAIvulnerability researchWAGO

Forescout Research — Vedere Labs published an experiment on 1 September with something most AI-and-OT commentary lacks: a receipt. The team set out to port CVE-2021-31886, a pre-authentication buffer overflow in the Nucleus FTP server, from a WAGO 750-852 reference PLC to a WAGO 750-831 target running firmware V01.04.16, using an AI model as the primary worker.

It succeeded, and the cost is the finding. The remote-code-execution development stage alone consumed 8 hours 32 minutes and $535.74 in API tokens, with roughly 2.6k input tokens against 1.3M output tokens for that stage. The team started on Claude Sonnet 4.6 with a 200k context window and switched to Claude Opus 4.6 with a 1M window; after the switch, two separate working payloads appeared within twelve minutes.

The work broke into five stages: confirming the vulnerability through static analysis and live probing, identifying target-specific parameters such as function addresses, offsets and memory regions, developing the exploit to controlled arbitrary ARM shellcode execution, generating post-exploitation payloads with ICMP and UDP beacons, and attempting a command-and-control extension.

That last stage permanently bricked the device by writing to flash memory — a detail worth dwelling on. Reconnaissance and exploit development against production controllers carry physical consequences, and that is as true for a red team with authorisation as for an attacker without one.

Forescout's conclusion is measured: AI can port OT exploits, but not unaided. The researchers navigated dead ends throughout and had to supply critical disassembly context by hand. Human experts remain faster and cheaper than the AI-assisted path today. What the team flags as the forward risk is not capability but economics — the same work parallelised across many device models at low marginal cost.

For anyone defending a plant, two things follow. The attack path ran through a legacy embedded TCP/IP stack, which argues for auditing what network services field devices still expose and disabling the ones nobody uses. And the price tag is now a known quantity: roughly a working day and the cost of a decent multimeter to weaponise a published CVE against a device model that has no public exploit. That number will not go up.

Source: Forescout Research — Vedere Labs

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.