Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
References
| Link | Resource |
|---|---|
| https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-arrayos-ag-vpn-flaw-to-plant-webshells/ | Press/Media Coverage |
| https://www.jpcert.or.jp/at/2025/at250024.html | Third Party Advisory |
| https://x.com/ArraySupport/status/1921373397533032590 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66644 | US Government Resource |
Configurations
Configuration 1 (hide)
| AND |
|
History
09 Dec 2025, 18:45
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:arraynetworks:ag1200:-:*:*:*:*:*:*:* cpe:2.3:h:arraynetworks:ag1200v5:-:*:*:*:*:*:*:* cpe:2.3:h:arraynetworks:ag1150:-:*:*:*:*:*:*:* cpe:2.3:h:arraynetworks:ag1100:-:*:*:*:*:*:*:* cpe:2.3:h:arraynetworks:ag1500v5:-:*:*:*:*:*:*:* cpe:2.3:h:arraynetworks:ag1600:-:*:*:*:*:*:*:* cpe:2.3:h:arraynetworks:ag1500:-:*:*:*:*:*:*:* cpe:2.3:o:arraynetworks:arrayos_ag:*:*:*:*:*:*:*:* cpe:2.3:h:arraynetworks:ag1600v5:-:*:*:*:*:*:*:* cpe:2.3:h:arraynetworks:ag1100v5:-:*:*:*:*:*:*:* cpe:2.3:h:arraynetworks:vxag:-:*:*:*:*:*:*:* cpe:2.3:h:arraynetworks:ag1500fips:-:*:*:*:*:*:*:* cpe:2.3:h:arraynetworks:ag1000t:-:*:*:*:*:*:*:* cpe:2.3:h:arraynetworks:ag1000v5:-:*:*:*:*:*:*:* cpe:2.3:h:arraynetworks:ag1000:-:*:*:*:*:*:*:* |
|
| First Time |
Arraynetworks vxag
Arraynetworks ag1000v5 Arraynetworks ag1200 Arraynetworks arrayos Ag Arraynetworks ag1600 Arraynetworks ag1200v5 Arraynetworks ag1500 Arraynetworks ag1100v5 Arraynetworks ag1100 Arraynetworks ag1150 Arraynetworks ag1000 Arraynetworks ag1600v5 Arraynetworks ag1500fips Arraynetworks ag1500v5 Arraynetworks ag1000t Arraynetworks |
|
| References | () https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-arrayos-ag-vpn-flaw-to-plant-webshells/ - Press/Media Coverage | |
| References | () https://www.jpcert.or.jp/at/2025/at250024.html - Third Party Advisory | |
| References | () https://x.com/ArraySupport/status/1921373397533032590 - Third Party Advisory | |
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66644 - US Government Resource |
08 Dec 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
05 Dec 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-05 19:15
Updated : 2025-12-09 18:45
NVD link : CVE-2025-66644
Mitre link : CVE-2025-66644
CVE.ORG link : CVE-2025-66644
JSON object : View
Products Affected
arraynetworks
- ag1600v5
- ag1200
- ag1200v5
- ag1000t
- ag1500fips
- ag1100
- ag1150
- arrayos_ag
- ag1000v5
- ag1600
- ag1500v5
- ag1100v5
- ag1000
- ag1500
- vxag
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
