AI Tool Used to Adapt Industrial Control System Exploit Across PLC Models
Researchers from Forescout's Vedere Labs used Anthropic's Claude AI model to adapt a working pre-authentication remote code execution (RCE) exploit originally built for one WAGO programmable logic controller (PLC) so it worked against a different WAGO model. The underlying flaw, tracked as CVE-2021-31886, is a stack-based buffer overflow in the Nucleus FTP server component used by these devices, triggered through the FTP 'USER' command. In their test, the researchers successfully executed attacker-supplied shellcode on live hardware.
The research is significant because it shows AI tools can lower the technical barrier for adapting existing exploits to new targets, even in specialised operational technology (OT) environments like industrial PLCs. While the underlying vulnerability was already known and patched information may exist, the demonstration underscores that threat actors could increasingly use AI to speed up reconnaissance and exploit modification work that once required deep manual expertise.
For small and medium businesses that rely on industrial or embedded control systems—such as manufacturers, utilities, or facilities with automated equipment—this is a reminder that OT devices connected to networks are attractive and increasingly accessible targets. Ensuring these systems are patched, segmented from corporate IT networks, and not exposed to the internet remains essential.