CVE Explorer
CVE-2025-66644
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
Known exploited
CISA KEV
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"ArrayOS AG","vendor":"Array Networks","versions":[{"lessThan":"9.4.5.9","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:aedd01818e2719444d006a0300ab73476165b0663eec650759afba9b665e181e · sha256:874ac30344b531ed… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":7.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:aedd01818e2719444d006a0300ab73476165b0663eec650759afba9b665e181e · sha256:874ac30344b531ed… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-78","description":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:aedd01818e2719444d006a0300ab73476165b0663eec650759afba9b665e181e · sha256:874ac30344b531ed… · /containers/cna/problemTypes/0/descriptions/0
Known exploitation assertions
2 source assertions{"cwes":["CWE-78"],"dateAdded":"2025-12-08","dueDate":"2025-12-29","knownRansomwareCampaignUse":"Unknown","notes":"https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/ag.html ; https://www.jpcert.or.jp/at/2025/at250024.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-66644","product":"ArrayOS AG","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Array Networks ArrayOS AG contains an OS command injection vulnerabili…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:c6408eced274883890fdbeda3874627d6e4bb0a31ac0ef222b4a72f848d64ac9 · sha256:16acee8334e59e44… · /vulnerabilities/188Open source location →
{"cwes":["CWE-78"],"dateAdded":"2025-12-08","dueDate":"2025-12-29","knownRansomwareCampaignUse":"Unknown","notes":"https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/ag.html ; https://www.jpcert.or.jp/at/2025/at250024.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-66644","product":"ArrayOS AG","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Array Networks ArrayOS AG contains an OS command injection vulnerabili…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:68bfac3b7e5982e5db5a55c3883e484c8661b8df6b4fe5929cb792afc5615b9f · sha256:635dff916c4092c0… · /vulnerabilities/191Open source location →
Source references
4 source assertions{"url":"https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-arrayos-ag-vpn-flaw-to-plant-webshells/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aedd01818e2719444d006a0300ab73476165b0663eec650759afba9b665e181e · sha256:874ac30344b531ed… · /containers/cna/references/2
{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66644"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aedd01818e2719444d006a0300ab73476165b0663eec650759afba9b665e181e · sha256:874ac30344b531ed… · /containers/adp/0/references/0
{"url":"https://www.jpcert.or.jp/at/2025/at250024.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aedd01818e2719444d006a0300ab73476165b0663eec650759afba9b665e181e · sha256:874ac30344b531ed… · /containers/cna/references/0
{"url":"https://x.com/ArraySupport/status/1921373397533032590"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:aedd01818e2719444d006a0300ab73476165b0663eec650759afba9b665e181e · sha256:874ac30344b531ed… · /containers/cna/references/1
Attribution and limitations
- CISA Known Exploited Vulnerabilities JSON: CISA named for provenance; do not use CISA/DHS marks or imply endorsement Source →
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.