JPCERT/CC Reports Widespread Exploitation of Array Networks AG Gateway Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-28461 | Unauthenticated RCE in Array Networks AG/vxAG SSL VPN Gateways (ArrayOS) CVE-2023-28461 is a critical (CVSS 9.8) missing-authentication flaw in Array Networks' AG series and virtual vxAG SSL VPN gateways running ArrayOS 9.4.0.481 and earlier. An unauthenticated remote attacker sends an HTTP request to a vulnerable URL containing a 'flags' attribute in an HTTP header, which allows browsing the filesystem on the SSL VPN gateway; vendor and CERT reporting indicate this can be leveraged into full remote code execution, and JPCERT has confirmed active command-injection attacks. Successful exploitation gives the attacker code execution on the appliance, compromising the VPN gateway and potentially providing a foothold into the protected internal network. Any organization running an affected AG/vxAG gateway is exposed; these are enterprise SSL VPN appliances, with notable deployments in Japan and the wider Asia-Pacific region. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-11-25 (ransomware use known), JPCERT/CC reports widespread exploitation, Chinese-linked activity including MirrorFace targeting Japanese firms has been reported, and EPSS places the 30-day exploitation probability at 68.1%. Do: Upgrade AG/vxAG gateways to a fixed ArrayOS release per Array Networks' instructions — as of the 2023-03-09 advisory a fixed release was pending, so apply any release newer than 9.4.0.481 once available; if mitigations are unavailable, discontinue use per the CISA KEV required action, and federal agencies should follow CISA's directive to patch. Review gateway logs and downstream systems for signs of exploitation, and treat any compromised appliance as a potential network foothold given confirmed ransomware use. | 9.8 | 68% | KEV ransomware |
| moderatelikely on the order of thousands (roughly 1,000–10,000) of internet-exposed AG/vxAG gateway appliances, each typically serving many remote users (estimate) |
Full article419 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 05, 2025

Array Networks AG gateways have been under active exploitation since August 2025 due to a command injection flaw, JPCERT/CC warns.
A command injection flaw in Array Networks AG Series gateways, affecting DesktopDirect, has been exploited in the wild since August 2025; it was patched in May 2025.
An attacker can exploit the flaw to execute arbitrary commands.
“The DesktopDirect function of the Array AG series provided by Array Networks contains a command injection vulnerability. An attacker exploiting this vulnerability could execute arbitrary commands. At the time of publishing this information, no CVE number has been assigned to this vulnerability. Array” reads the alert published by JPCERT/CC.
Array’s DesktopDirect is a remote desktop access solution designed to let users securely access their work computers from anywhere. It is commonly used in enterprise environments to provide employees with remote access to their office desktops, applications, and resources while maintaining security through encryption, authentication, and access controls.
The flaw affects ArrayOS AG 9.4.5.8 and earlier versions, the company addressed the flaw on May 11, 2025, with the release of ArrayOS AG 9.4.5.9.
The Japanese agency warns that since August 2025, domestic organizations using Array Networks products have faced attacks exploiting a command injection flaw, involving webshell installation, creation of new users, and internal intrusions. The attack traffic was traced to IP 194.233.100[.]138. Users should review Array Networks guidance and investigate potential compromises.
JPCERT advises organizations using Array Networks AG Series or DesktopDirect to carefully investigate their systems for any signs of intrusion, particularly considering that the vulnerability has been actively exploited since August 2025. Users should implement countermeasures and apply security patches provided by Array Networks or its authorized distributors to mitigate the risk. Where a full patch is not yet feasible, organizations are encouraged to follow any temporary workarounds suggested by the vendor to reduce potential exposure. The overall aim is to detect past breaches, prevent further exploitation, and ensure that remote access systems remain secure.
In November 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Array Networks AG and vxAG ArrayOS flaw CVE-2023-28461 (CVSS score: 9.8) to its Known Exploited Vulnerabilities (KEV) catalog.
Array Networks’ AG Series and vxAG (versions 9.4.0.481 and earlier) is impacted by a remote code execution vulnerability. Attackers can exploit the SSL VPN gateway by accessing the filesystem via an HTTP header flags attribute and a vulnerable URL without authentication.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Array Networks)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185358/uncategorized/jpcert-cc-reports-widespread-exploitation-of-array-networks-ag-gateway-vulnerability.html