CVE-2025-66644
KEVmoderateActively Exploited OS Command Injection in Array Networks ArrayOS AG
CISA: Array Networks ArrayOS AG OS Command Injection Vulnerability
Array Networks ArrayOS AG versions prior to 9.4.5.9 contain an OS command injection flaw (CWE-78) in the operating system that runs the vendor's AG series secure access (SSL VPN) gateways. The flaw is reachable over the network and requires no privileges or user interaction (CVSS AV:N/PR:N), meaning an unauthenticated remote attacker can inject operating-system commands through a network-exposed interface on the appliance and have them executed on the underlying OS. Successful exploitation gives the attacker full compromise of the gateway (high confidentiality, integrity, and availability impact), potentially exposing VPN user credentials, session traffic, and any internal networks reachable through the device. Any organization running an Array AG gateway on ArrayOS AG before 9.4.5.9 is affected, primarily enterprises and government-style access infrastructures. The flaw has been exploited in the wild from August through December 2025, was added to CISA's KEV on 2025-12-08, and JPCERT has confirmed active command injection attacks against Array AG gateways; no public proof-of-concept is known.
What to do: Upgrade affected Array AG appliances to ArrayOS AG 9.4.5.9 or later per the vendor's instructions, or apply vendor mitigations and comply with BOD 22-01 guidance if applicable. Until patched, restrict the appliance's management and VPN interfaces to trusted source addresses with firewall/ACL rules and treat the device as at high risk. Because exploitation has been ongoing since August 2025, review appliance logs for signs of command injection, rotate credentials and any VPN secrets or certificates stored on or reachable from the gateway, and check for signs of post-exploitation on connected internal systems.
| Array Networks ArrayOS AG | before 9.4.5.9 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
- Affected
- Array Networks ArrayOS AG
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- arraynetworks
- Products
- arrayos ag
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H