AI Used to Port PLC Exploit Raises Concerns Over Industrial Security

AI Used to Port PLC Exploit Raises Concerns Over Industrial Security

First seen 1 Sep 2026, 12:59 UTC ItproFeeds.Feedburner 51.9

Article Content

Browse articles
ThreatCluster

Researchers at Forescout’s Vedere Labs successfully ported a remote code execution (RCE) exploit between two WAGO PLC models, specifically targeting CVE-2021-31886, a pre-authentication buffer overflow in the Nucleus FTP server. The experiment took over eight hours and cost approximately $535 in API tokens, highlighting the significant human oversight still required despite AI assistance. Initial attempts at exploit development faced challenges, including incorrect hypotheses and dead ends, but after switching to Claude Opus 4.6 and refining prompts, the AI produced working payloads rapidly. The experiment underscores the potential for AI to automate post-exploitation activities, raising alarms about the accessibility of such techniques for malicious actors. As AI-assisted exploit development improves, the risk to industrial systems could increase significantly.

Key Points: • AI successfully ported an RCE exploit targeting WAGO PLCs, specifically CVE-2021-31886. • The experiment required over eight hours and $535 in API costs, emphasizing human oversight. • AI's ability to automate post-exploitation could make attacks on industrial systems more accessible.

Timeline

2021-11-09
CVE-2021-31886 published
A pre-authentication buffer overflow in the Nucleus FTP server allows arbitrary ARM shellcode execution on WAGO PLCs.
Feeds.Feedburner
2026-09-01
AI-assisted exploit development completed
Forescout researchers ported an RCE exploit between WAGO PLC models, achieving code execution after extensive human guidance.
Itpro