CVE-2025-66644

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:arraynetworks:arrayos_ag:*:*:*:*:*:*:*:*
OR cpe:2.3:h:arraynetworks:ag1000:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1000t:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1000v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1100:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1100v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1150:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1200:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1200v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1500:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1500fips:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1500v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1600:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1600v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:vxag:-:*:*:*:*:*:*:*

History

09 Dec 2025, 18:45

Type Values Removed Values Added
CPE cpe:2.3:h:arraynetworks:ag1200:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1200v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1150:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1100:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1500v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1600:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1500:-:*:*:*:*:*:*:*
cpe:2.3:o:arraynetworks:arrayos_ag:*:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1600v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1100v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:vxag:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1500fips:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1000t:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1000v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1000:-:*:*:*:*:*:*:*
First Time Arraynetworks vxag
Arraynetworks ag1000v5
Arraynetworks ag1200
Arraynetworks arrayos Ag
Arraynetworks ag1600
Arraynetworks ag1200v5
Arraynetworks ag1500
Arraynetworks ag1100v5
Arraynetworks ag1100
Arraynetworks ag1150
Arraynetworks ag1000
Arraynetworks ag1600v5
Arraynetworks ag1500fips
Arraynetworks ag1500v5
Arraynetworks ag1000t
Arraynetworks
References () https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-arrayos-ag-vpn-flaw-to-plant-webshells/ - () https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-arrayos-ag-vpn-flaw-to-plant-webshells/ - Press/Media Coverage
References () https://www.jpcert.or.jp/at/2025/at250024.html - () https://www.jpcert.or.jp/at/2025/at250024.html - Third Party Advisory
References () https://x.com/ArraySupport/status/1921373397533032590 - () https://x.com/ArraySupport/status/1921373397533032590 - Third Party Advisory
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66644 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66644 - US Government Resource

08 Dec 2025, 19:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66644 -

05 Dec 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-05 19:15

Updated : 2025-12-09 18:45


NVD link : CVE-2025-66644

Mitre link : CVE-2025-66644

CVE.ORG link : CVE-2025-66644


JSON object : View

Products Affected

arraynetworks

  • ag1600v5
  • ag1200
  • ag1200v5
  • ag1000t
  • ag1500fips
  • ag1100
  • ag1150
  • arrayos_ag
  • ag1000v5
  • ag1600
  • ag1500v5
  • ag1100v5
  • ag1000
  • ag1500
  • vxag
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')