Forescout warns AI lowers barriers to PLC exploit development but human expertise remains essential

Researchers used AI to port a working PLC exploit across WAGO models, costing $535.74 in API tokens for a single target while requiring substantial human guidance.

Categorized in: AI News IT and Development
Published on: Sep 08, 2026
Forescout warns AI lowers barriers to PLC exploit development but human expertise remains essential

Researchers at Forescout Technologies used AI to port a working remote code execution exploit from one WAGO programmable logic controller model to another, demonstrating that AI-assisted exploitation can reach low-level operational technology environments. The exercise produced an exploit capable of executing attacker-supplied ARM shellcode on a live PLC, though the process required substantial human guidance and cost $535.74 in API tokens for a single target.

"AI has already lowered the barrier to vulnerability research and exploit development in higher-level software. This experiment suggests that the same progression is beginning to reach low-level embedded systems, although substantial barriers remain," Amine Amri and Forescout Research - Vedere Labs wrote in a blog post. "As models become more capable and independent, the cost and expertise required to adapt exploits across related embedded targets could fall substantially."

The research targeted a pre-authentication buffer overflow in the Nucleus FTP server. Forescout had already developed a working RCE exploit for the WAGO 750-852 PLC, which injected ARM shellcode to rewrite HTML on the device's web interface. The new work aimed to port that exploit to the WAGO 750-831 and test whether AI could extend it into a command-and-control implant.

How the AI-assisted exploit development worked

The process involved two main stages: confirming the vulnerability and writing the payload. Researchers used Claude Code, which had access to a terminal, reference files, reverse-engineering tools including Ghidra, and a live target PLC. The AI could directly use these tools, generate and test code, and request guidance when needed.

During vulnerability confirmation, Claude Sonnet 4.6 initially identified a potential buffer overflow distinct from the known CVE-2021-31886 vulnerability. Researchers set that finding aside and launched a new session focused on the known vulnerability. Claude validated it by probing the PLC's FTP service and performing static firmware analysis with Ghidra and AI-generated Python scripts.

The process required multiple sessions and researcher intervention. An initial analysis produced an invalid exploit, but its findings helped a later session correctly map the relevant functions through binary searches and additional disassembly review. The final RCE development stage took 8 hours and 32 minutes.

Current limitations and costs

The experiment revealed significant barriers. The $535.74 API cost covered a single exploit against one target. An attempt to extend the exploit into a command-and-control implant ultimately bricked the PLC. Forescout said an experienced researcher could likely complete the initial exploit port faster and cheaper without AI under current conditions.

Despite these limitations, the researchers warned that the traditional assumption that attackers favor engineering protocols over complex PLC exploits may become less reliable. "Once initial code execution was achieved, AI generated multiple working network payloads within minutes, suggesting that post-exploitation could become increasingly automated as models improve," the researchers wrote.

The work is part of a broader pattern in cybersecurity. For IT and development professionals tracking how AI changes the threat landscape, these findings align with what the AI Learning Path for Cybersecurity Analysts covers: automation is compressing timelines that once required deep specialization.

Defensive implications for critical infrastructure

Forescout called on organizations to prioritize risk based on reachability, exploitability, and process impact. OT vulnerabilities should be treated differently from conventional IT findings by considering device role, network exposure, compensating controls, and potential operational consequences. As AI reduces the effort required for exploit development, "hard to exploit" becomes a weaker reason for deprioritizing a vulnerable controller.

Organizations should reduce unnecessary exposure of OT devices by disabling or restricting high-risk services such as FTP, Telnet, and web administration interfaces. They should implement secure remote access that replaces flat VPN access and shared credentials with brokered, least-privilege access. Security teams should also monitor OT behavior for unusual protocol use, repeated crashes, unexpected outbound communication, and changes in device behavior.

The researchers recommended using AI defensively to accelerate firmware triage, advisory analysis, detection engineering, and exposure reviews, while keeping human experts in the loop for safety-critical decisions. The same limitations observed in the research, including false leads and unsafe assumptions, also apply to defensive automation.

Why this matters for IT and development professionals

For teams responsible for securing infrastructure or developing embedded systems, this research signals a shift in threat modeling assumptions. Exploits that once required weeks of specialist reverse-engineering may soon be ported across device families with AI assistance at declining cost. The experiment also demonstrates that AI-generated exploits can produce noisy or unstable artifacts that defenders can use for detection. Incident response plans should account for scenarios where attackers rapidly adapt exploits across device models or cause device instability through failed exploitation. Professionals looking to build defensive AI skills can explore AI for IT & Development resources that address these emerging attack patterns.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)