CRITICAL
CVE-2025-66644
CVSS
9.8
KEV
Description
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
Summary dbcve.org
Array Networks ArrayOS AG versions before 9.4.5.9 contain a command injection vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands on the affected appliance, likely through insufficient input validation in web interface parameters.
Mitigation
Immediately upgrade ArrayOS AG to version 9.4.5.9 or later to remediate this vulnerability. If immediate patching is not possible, restrict network access to the management interface and monitor for indicators of compromise.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
3.42%
Probability of exploitation in next 30 days
88.4th percentile
References
https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-arrayos-ag-vpn-flaw-to-plant-webshells/
Press/Media Coverage
https://www.jpcert.or.jp/at/2025/at250024.html
Third Party Advisory
https://x.com/ArraySupport/status/1921373397533032590
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66644
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.