Forescout’s Vedere Labs spent eight and a half hours and 535.74 dollars in API costs getting Claude to port a known remote-code-execution exploit from one WAGO programmable logic controller to a related but distinct model. That is not, on its face, an alarming result. It is also the wrong number to focus on.
The vulnerability itself, CVE-2021-31886, is not new. It is a five-year-old buffer overflow in the Nucleus FTP server that Vedere Labs had already turned into a working, pre-authentication exploit on a WAGO 750-852 controller. What the researchers tested was narrower and, for an operational technology defender, more consequential: could an AI model take an exploit that already works on one product and adapt it to a sibling model it has never touched, using nothing but a firmware binary, disassembly context and a live target. It could. It took a working researcher, a full day, and real trial and error, including one payload that permanently bricked the test PLC. But it worked.
The counter-argument, stated plainly
The honest rebuttal to treating this as a five-alarm finding is the cost and effort involved. Eight hours of sustained, expert-guided interactive sessions with an AI model is not a script an unskilled attacker runs overnight. Vedere Labs itself frames the result as evidence that low-level embedded exploitation still requires substantial expertise, not evidence that it has become trivial. A defender could reasonably read this experiment and conclude the sky has not fallen: real ICS exploitation still needs a real researcher steering the process, and $536 in tokens is not nothing.
That is a fair reading of this one experiment. It is the wrong reading of the trend it sits inside, the same trend CyberTech flagged when researchers first used AI to write original exploits for Siemens PLCs rather than merely port an existing one.
Why the trend, not the number, is the story
The value of a working exploit for one hardware model has always rested partly on an assumption defenders rarely state out loud: that a proof-of-concept written for Model A is a meaningfully different problem from the same bug class sitting unexploited in Model B, C and D from the same vendor family, because porting it takes specialist reverse-engineering work most attackers will not bother doing for a mid-tier industrial target. That assumption is what let plenty of security teams deprioritize patching a vulnerability on a device where “no public exploit exists for our exact model” was treated as a real mitigating factor.
What this experiment shows is that the gap between “an exploit exists somewhere in this product family” and “an exploit exists for the box in front of me” is now a function of researcher time and API spend rather than specialist scarcity. Vedere Labs did not discover a new vulnerability class or invent a new technique. It automated the boring, expensive part, adapting a known-good exploit to a new target, that previously made cross-model porting uneconomical for anything short of a well-resourced actor. Costs for that kind of work only go one direction from here, and it is down.
What it means for the security leader
The practical consequence is not that every organization running a WAGO PLC needs to panic about this specific CVE, which Siemens and WAGO have already rated and which has a five-year-old patch trail. It is that “too specialized to be worth exploiting broadly” needs to come off the list of reasons an OT vulnerability gets deprioritized. Forescout’s own recommendation, disabling unnecessary exposed services like FTP and Telnet and replacing flat VPN access to industrial equipment with something more segmented, is not new advice. What is new is the argument for doing it now rather than on the next budget cycle: the economics that used to protect an obscure PLC model by making it not worth an attacker’s time are eroding, and they are eroding in a direction that favors whoever automates the adaptation work first.
Incident response plans built around a single hardware model or firmware version should be revisited with the assumption that an exploit developed against a sibling device is now a realistic, not theoretical, escalation path, the IT-side version of the shift already underway where attackers increasingly ask an AI agent to do the exploitation work instead of writing it themselves. That is a planning problem, not a patching emergency, and it belongs on the same list as network segmentation and exposure reduction rather than a fire drill. But it belongs on the list. Vedere Labs bricked its own test hardware trying to push this further, a reminder that AI-assisted exploitation is not yet reliable even for the people doing it on purpose. Reliability is exactly the kind of gap that shrinks with each iteration, and it is not the defender’s side of that gap that is closing.
Source: Forescout Vedere Labs
