AI-Powered PLC Exploit Porting: Time and Cost Analysis

www.news4hackers.com-ai-powered-plc-exploit-porting-time-and-cost-analysis-ai-powered-plc-exploit-porting-time-and-cost-analysis

A team from Forescout’s Vedere Labs conducted an experiment to evaluate the feasibility of using artificial intelligence to adapt a remote code execution (RCE) exploit targeting a WAGO programmable logic controller (PLC) to a different model.

Experiment Overview

A team from Forescout’s Vedere Labs conducted an experiment to evaluate the feasibility of using artificial intelligence to adapt a remote code execution (RCE) exploit targeting a WAGO programmable logic controller (PLC) to a different model. The project involved leveraging Anthropic’s Claude Code model to transition an existing exploit for the WAGO 750-852 PLC, which exploits CVE-2021-31886, a pre-authentication buffer overflow vulnerability in the Nucleus FTP server. This flaw enables unauthenticated attackers to execute arbitrary ARM shellcode on the device. The goal was to modify the exploit for the WAGO 750-831 model and assess whether the AI could advance the payload to a functional command-and-control implant.

Methodology and Tools

The researchers provided Claude Code with access to a terminal environment, reference documentation, the reverse-engineering tool Ghidra, and a physical WAGO 750-831 device. The AI first validated the vulnerability through a combination of live testing and static firmware analysis, generating a payload that triggered a system crash. This confirmed the presence of the flaw but marked only the initial phase of the task.

Challenges and Breakthroughs

Achieving controlled code execution proved significantly more challenging, as early attempts by the AI produced inconsistent results, requiring manual intervention to correct misdirections and provide additional technical context. A critical breakthrough occurred after the team upgraded to Claude Opus 4.6 and instructed the model to request assistance when encountering ambiguous firmware details. The AI eventually identified why injected code was being erased before execution, adjusting its approach to ensure payload persistence.

The researchers noted that this pattern—initial difficulty in achieving execution followed by rapid iteration—highlights the potential for AI to reduce costs in scalable operations, though current reliance on human oversight remains substantial.

Costs and Limitations

Within 12 minutes, the system generated two functional payloads for the target PLC. A subsequent attempt to develop a command-and-control implant encountered significant obstacles. During testing, a payload inadvertently wrote to a memory region mapped to the PLC’s flash storage, permanently damaging the device. The experiment’s final phase, focused on refining the RCE, incurred over $500 in API costs across an eight-hour session.

Conclusion and Future Outlook

The team acknowledged that a human researcher could achieve similar results more efficiently and with lower risk but emphasized the long-term implications of reducing expert intervention. While AI cannot yet replace human expertise, its capacity to parallelize tasks across multiple targets could lower marginal costs as its capabilities evolve. The study underscores the growing intersection of artificial intelligence and cybersecurity, particularly in exploit development. While the current process remains resource-intensive, the experiment suggests that AI tools may eventually streamline complex tasks, though their practical application will depend on continued advancements in model accuracy and reduced reliance on manual oversight.



About Author

en_USEnglish