
This is an important challenge because different PLC models from the same vendor or even different manufacturers might share a vulnerable component, with the rest of the firmware being significantly different. Furthermore, vendors sometimes patch a vulnerability reported in one model without comprehensively assessing whether the same flaw affects others in their product line.
For example, back in June, Forescout reported seeing exploit attempts for a vulnerability they found and reported in serial-to-IP converters from Lantronix (CVE-2025-67038). The manufacturer originally released patches only for the EDS5000 and EDS3000 series of controllers, but after in-the-wild exploitation came to light four months later, it identified and released patches for additional device models: G520 series, X300 series, E210 and E220 series.
“I do believe that in case manufacturers do not perform a comprehensive assessment of models affected by a vulnerability, AI can now help attackers to do it and to port exploits to models that may not have been patched,” Daniel dos Santos, VP of research at Forescout, tells CSO.
