ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

JPCERT Confirms Active Command Injection Attacks on Array AG Gateways

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-28461CVE-2025-66644

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-28461
Unauthenticated RCE in Array Networks AG/vxAG SSL VPN Gateways (ArrayOS)

CVE-2023-28461 is a critical (CVSS 9.8) missing-authentication flaw in Array Networks' AG series and virtual vxAG SSL VPN gateways running ArrayOS 9.4.0.481 and earlier. An unauthenticated remote attacker sends an HTTP request to a vulnerable URL containing a 'flags' attribute in an HTTP header, which allows browsing the filesystem on the SSL VPN gateway; vendor and CERT reporting indicate this can be leveraged into full remote code execution, and JPCERT has confirmed active command-injection attacks. Successful exploitation gives the attacker code execution on the appliance, compromising the VPN gateway and potentially providing a foothold into the protected internal network. Any organization running an affected AG/vxAG gateway is exposed; these are enterprise SSL VPN appliances, with notable deployments in Japan and the wider Asia-Pacific region. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-11-25 (ransomware use known), JPCERT/CC reports widespread exploitation, Chinese-linked activity including MirrorFace targeting Japanese firms has been reported, and EPSS places the 30-day exploitation probability at 68.1%.

Do: Upgrade AG/vxAG gateways to a fixed ArrayOS release per Array Networks' instructions — as of the 2023-03-09 advisory a fixed release was pending, so apply any release newer than 9.4.0.481 once available; if mitigations are unavailable, discontinue use per the CISA KEV required action, and federal agencies should follow CISA's directive to patch. Review gateway logs and downstream systems for signs of exploitation, and treat any compromised appliance as a potential network foothold given confirmed ransomware use.

9.868% KEV ransomware
  • Array Networks AG series and vxAG SSL VPN gateways (ArrayOS) 9.4.0.481 and earlier
moderatelikely on the order of thousands (roughly 1,000–10,000) of internet-exposed AG/vxAG gateway appliances, each typically serving many remote users (estimate)
CVE-2025-66644
Actively Exploited OS Command Injection in Array Networks ArrayOS AG

Array Networks ArrayOS AG versions prior to 9.4.5.9 contain an OS command injection flaw (CWE-78) in the operating system that runs the vendor's AG series secure access (SSL VPN) gateways. The flaw is reachable over the network and requires no privileges or user interaction (CVSS AV:N/PR:N), meaning an unauthenticated remote attacker can inject operating-system commands through a network-exposed interface on the appliance and have them executed on the underlying OS. Successful exploitation gives the attacker full compromise of the gateway (high confidentiality, integrity, and availability impact), potentially exposing VPN user credentials, session traffic, and any internal networks reachable through the device. Any organization running an Array AG gateway on ArrayOS AG before 9.4.5.9 is affected, primarily enterprises and government-style access infrastructures. The flaw has been exploited in the wild from August through December 2025, was added to CISA's KEV on 2025-12-08, and JPCERT has confirmed active command injection attacks against Array AG gateways; no public proof-of-concept is known.

Do: Upgrade affected Array AG appliances to ArrayOS AG 9.4.5.9 or later per the vendor's instructions, or apply vendor mitigations and comply with BOD 22-01 guidance if applicable. Until patched, restrict the appliance's management and VPN interfaces to trusted source addresses with firewall/ACL rules and treat the device as at high risk. Because exploitation has been ongoing since August 2025, review appliance logs for signs of command injection, rotate credentials and any VPN secrets or certificates stored on or reachable from the gateway, and check for signs of post-exploitation on connected internal systems.

9.83% KEV
  • Array Networks ArrayOS AG before 9.4.5.9
moderateon the order of thousands to low tens of thousands of internet-exposed Array AG gateway appliances

Indicators of compromiseAll →

TypeIndicatorContext
ipv49.4.5.8st attack spree. The vulnerability impacts ArrayOS versions 9.4.5.8 and earlier, and has been addressed in version ArrayOS 9.4.
Full article416 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananDec 05, 2025Vulnerability / Network Security

A command injection vulnerability in Array Networks AG Series secure access gateways has been exploited in the wild since August 2025, according to an alert issued by JPCERT/CC this week.

The vulnerability, which does not have a CVE identifier, was addressed by the company on May 11, 2025. It's rooted in Array's DesktopDirect, a remote desktop access solution that allows users to securely access their work computers from any location.

"Exploitation of this vulnerability could allow attackers to execute arbitrary commands," JPCERT/CC said. "This vulnerability affects systems where the 'DesktopDirect' feature, which provides remote desktop access, is enabled."

The agency said it has confirmed incidents in Japan that have exploited the shortcoming after August 2025 to drop web shells on susceptible devices. The attacks have originated from the IP address "194.233.100[.]138."

There are currently no details available on the scale of the attacks, weaponizing the flaw, and identity of the threat actors exploiting it.

However, an authentication bypass flaw in the same product (CVE-2023-28461, CVSS score: 9.8) was exploited last year by a China-linked cyber espionage group dubbed MirrorFace, which has a history of targeting Japanese organizations since at least 2019. That said, there is no evidence at this stage to suggest that the threat actor could be linked to the latest attack spree.

The vulnerability impacts ArrayOS versions 9.4.5.8 and earlier, and has been addressed in version ArrayOS 9.4.5.9. Users are advised to apply the latest updates as soon as possible to mitigate potential threats. In case patching is not an immediate option, it's recommended to disable DesktopDirect services and use URL filtering to deny access to URLs containing a semicolon, JPCERT/CC said.

Flaw Now Tracked as CVE-2025-66644

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday said the command injection vulnerability impacting Array Networks AG Series secure access gateways has been assigned the CVE identifier CVE-2025-66644 (CVSS score: 7.2).

"Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands," the agency said.

The vulnerability has been added to the Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by December 29, 2025.

(The story was updated after publication on December 9, 2025, with details of the CVE.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/12/jpcert-confirms-active-command.html