Known exploited
CISA KEV
Disputed
No
Stale source
No
Conflicts
0

Affected products and versions

1 source assertion
{"defaultStatus":"unaffected","product":"ArrayOS AG","vendor":"Array Networks","versions":[{"lessThan":"9.4.5.9","status":"affected","version":"0","versionType":"custom"}]}
  • cve_program_cvelist_v5affected
    urn:baitaphish:normalized-source-record:v2:aedd01818e2719444d006a0300ab73476165b0663eec650759afba9b665e181e · sha256:874ac30344b531ed… · /containers/cna/affected/0

Provider-owned CVSS observations

1 source assertion
{"metric":{"baseScore":7.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
  • cve_program_cvelist_v5cvss
    urn:baitaphish:normalized-source-record:v2:aedd01818e2719444d006a0300ab73476165b0663eec650759afba9b665e181e · sha256:874ac30344b531ed… · /containers/cna/metrics/0/cvssV3_1

CWE assertions

1 source assertion
{"cweId":"CWE-78","description":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
  • cve_program_cvelist_v5cwe
    urn:baitaphish:normalized-source-record:v2:aedd01818e2719444d006a0300ab73476165b0663eec650759afba9b665e181e · sha256:874ac30344b531ed… · /containers/cna/problemTypes/0/descriptions/0

Known exploitation assertions

2 source assertions
{"cwes":["CWE-78"],"dateAdded":"2025-12-08","dueDate":"2025-12-29","knownRansomwareCampaignUse":"Unknown","notes":"https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/ag.html ; https://www.jpcert.or.jp/at/2025/at250024.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-66644","product":"ArrayOS AG","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Array Networks ArrayOS AG contains an OS command injection vulnerabili…
  • cisa_kev_jsonknown_exploited
    urn:baitaphish:normalized-source-record:v2:c6408eced274883890fdbeda3874627d6e4bb0a31ac0ef222b4a72f848d64ac9 · sha256:16acee8334e59e44… · /vulnerabilities/188
    Open source location →
{"cwes":["CWE-78"],"dateAdded":"2025-12-08","dueDate":"2025-12-29","knownRansomwareCampaignUse":"Unknown","notes":"https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/ag.html ; https://www.jpcert.or.jp/at/2025/at250024.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-66644","product":"ArrayOS AG","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Array Networks ArrayOS AG contains an OS command injection vulnerabili…
  • cisa_kev_jsonknown_exploited
    urn:baitaphish:normalized-source-record:v2:68bfac3b7e5982e5db5a55c3883e484c8661b8df6b4fe5929cb792afc5615b9f · sha256:635dff916c4092c0… · /vulnerabilities/191
    Open source location →

Source references

4 source assertions
{"url":"https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-arrayos-ag-vpn-flaw-to-plant-webshells/"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:aedd01818e2719444d006a0300ab73476165b0663eec650759afba9b665e181e · sha256:874ac30344b531ed… · /containers/cna/references/2
{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66644"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:aedd01818e2719444d006a0300ab73476165b0663eec650759afba9b665e181e · sha256:874ac30344b531ed… · /containers/adp/0/references/0
{"url":"https://www.jpcert.or.jp/at/2025/at250024.html"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:aedd01818e2719444d006a0300ab73476165b0663eec650759afba9b665e181e · sha256:874ac30344b531ed… · /containers/cna/references/0
{"url":"https://x.com/ArraySupport/status/1921373397533032590"}
  • cve_program_cvelist_v5reference
    urn:baitaphish:normalized-source-record:v2:aedd01818e2719444d006a0300ab73476165b0663eec650759afba9b665e181e · sha256:874ac30344b531ed… · /containers/cna/references/1

Attribution and limitations

  • CISA Known Exploited Vulnerabilities JSON: CISA named for provenance; do not use CISA/DHS marks or imply endorsement Source →
  • CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →

Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.