Particle.news

AI Helped Port Remote Code‑Execution Exploit Between WAGO PLC Models

Forescout’s lab test shows that stronger AI could lower the time and cost needed to adapt exploits to industrial controllers.

Overview

  • Forescout Vedere Labs used Anthropic’s Claude to adapt a known RCE for the WAGO 750‑852 so it worked on a WAGO 750‑831, and the team publicly reported the work this week.
  • The trial confirmed the CVE‑2021‑31886 flaw via live probing and firmware analysis and produced a payload that crashed the PLC before researchers reached reliable code execution.
  • Developing a final working RCE required heavy human guidance, took about eight hours and 32 minutes, and used roughly $535.74 in API calls, showing the process is not yet autonomous.
  • After researchers switched Claude model variants and resolved a payload‑erasure issue, the AI generated multiple functioning payloads within minutes, illustrating rapid iteration once a key roadblock is cleared.
  • A later session that tried to build a command‑and‑control implant wrote to flash memory and permanently bricked the PLC, underscoring physical risks and the need for urgent OT measures such as blocking FTP, network segmentation, and monitoring.