CRITICAL

CVE-2025-66644

Arraynetworks Arrayos Ag 2025-12-05 CVSS v3.1
CVSS
9.8
KEV

Description

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

Summary dbcve.org

Array Networks ArrayOS AG versions before 9.4.5.9 contain a command injection vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands on the affected appliance, likely through insufficient input validation in web interface parameters.

Mitigation

Immediately upgrade ArrayOS AG to version 9.4.5.9 or later to remediate this vulnerability. If immediate patching is not possible, restrict network access to the management interface and monitor for indicators of compromise.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

3.42%
Probability of exploitation in next 30 days
88.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE