Turns out you can just hack any train in the USA and take control over the brakes. This is CVE-2025-1727 and it took me 12 years to get this published. This vulnerability is still not patched. Here's the story:
In the 1980's congress mandated a replacement to the caboose to reduce rail accidents. The industry responded with the 'Flashing Red End Device' or FRED, also known as an End-of-Train (EOT) that wirelessly reports telemetry back to the cab, but can also accept commands.