Vulnerabilities
7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-66644 | Actively Exploited OS Command Injection in Array Networks ArrayOS AG Array Networks ArrayOS AG versions prior to 9.4.5.9 contain an OS command injection flaw (CWE-78) in the operating system that runs the vendor's AG series secure access (SSL VPN) gateways. The flaw is reachable over the network and requires no privileges or user interaction (CVSS AV:N/PR:N), meaning an unauthenticated remote attacker can inject operating-system commands through a network-exposed interface on the appliance and have them executed on the underlying OS. Successful exploitation gives the attacker full compromise of the gateway (high confidentiality, integrity, and availability impact), potentially exposing VPN user credentials, session traffic, and any internal networks reachable through the device. Any organization running an Array AG gateway on ArrayOS AG before 9.4.5.9 is affected, primarily enterprises and government-style access infrastructures. The flaw has been exploited in the wild from August through December 2025, was added to CISA's KEV on 2025-12-08, and JPCERT has confirmed active command injection attacks against Array AG gateways; no public proof-of-concept is known. Do: Upgrade affected Array AG appliances to ArrayOS AG 9.4.5.9 or later per the vendor's instructions, or apply vendor mitigations and comply with BOD 22-01 guidance if applicable. Until patched, restrict the appliance's management and VPN interfaces to trusted source addresses with firewall/ACL rules and treat the device as at high risk. Because exploitation has been ongoing since August 2025, review appliance logs for signs of command injection, rotate credentials and any VPN secrets or certificates stored on or reachable from the gateway, and check for signs of post-exploitation on connected internal systems. | 9.8 | 3% | KEV |
| moderateon the order of thousands to low tens of thousands of internet-exposed Array AG gateway appliances | |
| CVE-2023-51707 | MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffected. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2023-41121 | Array AG OS before 9.4.0.499 allows denial of service: Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-28461 | Unauthenticated RCE in Array Networks AG/vxAG SSL VPN Gateways (ArrayOS) CVE-2023-28461 is a critical (CVSS 9.8) missing-authentication flaw in Array Networks' AG series and virtual vxAG SSL VPN gateways running ArrayOS 9.4.0.481 and earlier. An unauthenticated remote attacker sends an HTTP request to a vulnerable URL containing a 'flags' attribute in an HTTP header, which allows browsing the filesystem on the SSL VPN gateway; vendor and CERT reporting indicate this can be leveraged into full remote code execution, and JPCERT has confirmed active command-injection attacks. Successful exploitation gives the attacker code execution on the appliance, compromising the VPN gateway and potentially providing a foothold into the protected internal network. Any organization running an affected AG/vxAG gateway is exposed; these are enterprise SSL VPN appliances, with notable deployments in Japan and the wider Asia-Pacific region. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-11-25 (ransomware use known), JPCERT/CC reports widespread exploitation, Chinese-linked activity including MirrorFace targeting Japanese firms has been reported, and EPSS places the 30-day exploitation probability at 68.1%. Do: Upgrade AG/vxAG gateways to a fixed ArrayOS release per Array Networks' instructions — as of the 2023-03-09 advisory a fixed release was pending, so apply any release newer than 9.4.0.481 once available; if mitigations are unavailable, discontinue use per the CISA KEV required action, and federal agencies should follow CISA's directive to patch. Review gateway logs and downstream systems for signs of exploitation, and treat any compromised appliance as a potential network foothold given confirmed ransomware use. | 9.8 | 68% | KEV ransomware |
| moderatelikely on the order of thousands (roughly 1,000–10,000) of internet-exposed AG/vxAG gateway appliances, each typically serving many remote users (estimate) | |
| CVE-2023-28460 | A command injection vulnerability was discovered in Array Networks APV products. A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted packet after logging into the affected appliance as an administrator, resulting in arbitrary shell code execution. This is fixed in 8.6.1.262 or newer and 10.4.2.93 or newer. NVD description · AI analysis pending | 7.2 | 2% |
| — | ||
| CVE-2023-24613 | The user interface of Array Networks AG Series and vxAG through 9.4.0.470 could allow a remote attacker to use the gdb tool to overwrite the backend function ca The user interface of Array Networks AG Series and vxAG through 9.4.0.470 could allow a remote attacker to use the gdb tool to overwrite the backend function call stack after accessing the system with administrator privileges. A successful exploit could leverage this vulnerability in the backend binary file that handles the user interface to a cause denial of service attack. This is fixed in AG 9.4.0.481. NVD description · AI analysis pending | 4.9 | <1% |
| — | ||
| CVE-2022-42897 | Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x is unaffected. NVD description · AI analysis pending | 9.8 | 2% |
| — |