ZeroHour

CVE-2025-66644

KEVmoderate

Actively Exploited OS Command Injection in Array Networks ArrayOS AG

CISA: Array Networks ArrayOS AG OS Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
3%p88
Published
()
KEV added
AI analysis

Array Networks ArrayOS AG versions prior to 9.4.5.9 contain an OS command injection flaw (CWE-78) in the operating system that runs the vendor's AG series secure access (SSL VPN) gateways. The flaw is reachable over the network and requires no privileges or user interaction (CVSS AV:N/PR:N), meaning an unauthenticated remote attacker can inject operating-system commands through a network-exposed interface on the appliance and have them executed on the underlying OS. Successful exploitation gives the attacker full compromise of the gateway (high confidentiality, integrity, and availability impact), potentially exposing VPN user credentials, session traffic, and any internal networks reachable through the device. Any organization running an Array AG gateway on ArrayOS AG before 9.4.5.9 is affected, primarily enterprises and government-style access infrastructures. The flaw has been exploited in the wild from August through December 2025, was added to CISA's KEV on 2025-12-08, and JPCERT has confirmed active command injection attacks against Array AG gateways; no public proof-of-concept is known.

What to do: Upgrade affected Array AG appliances to ArrayOS AG 9.4.5.9 or later per the vendor's instructions, or apply vendor mitigations and comply with BOD 22-01 guidance if applicable. Until patched, restrict the appliance's management and VPN interfaces to trusted source addresses with firewall/ACL rules and treat the device as at high risk. Because exploitation has been ongoing since August 2025, review appliance logs for signs of command injection, rotate credentials and any VPN secrets or certificates stored on or reachable from the gateway, and check for signs of post-exploitation on connected internal systems.

Affected
Array Networks ArrayOS AGbefore 9.4.5.9
Estimated exposure
moderateon the order of thousands to low tens of thousands of internet-exposed Array AG gateway appliances — No public scan count is provided in the data, so this is extrapolated from Array Networks' niche enterprise SSL-VPN appliance footprint and typical internet-exposure counts for smaller VPN-gateway vendors; external scan data could revise…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

CISA Known Exploited Vulnerability
Affected
Array Networks ArrayOS AG
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
arraynetworks
Products
arrayos ag
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news