Overview
- Forescout Vedere Labs used Anthropic’s Claude to adapt a known RCE for the WAGO 750‑852 so it worked on a WAGO 750‑831, and the team publicly reported the work this week.
- The trial confirmed the CVE‑2021‑31886 flaw via live probing and firmware analysis and produced a payload that crashed the PLC before researchers reached reliable code execution.
- Developing a final working RCE required heavy human guidance, took about eight hours and 32 minutes, and used roughly $535.74 in API calls, showing the process is not yet autonomous.
- After researchers switched Claude model variants and resolved a payload‑erasure issue, the AI generated multiple functioning payloads within minutes, illustrating rapid iteration once a key roadblock is cleared.
- A later session that tried to build a command‑and‑control implant wrote to flash memory and permanently bricked the PLC, underscoring physical risks and the need for urgent OT measures such as blocking FTP, network segmentation, and monitoring.