๐Ÿ”ด CVE-2025-66644

Critical OS command injection vulnerability in Array Networks ArrayOS AG VPN appliances affecting versions before 9.4.5.9. Active exploitation confirmed in the wild from August-December 2025 with attackers deploying webshells for persistent access.

โ† Back to Overview
HIGH_RISK
Risk Level
T1190
MITRE Technique
7.2
CVSS Score
NETWORK
Attack Vector
VERY_HIGH
Deployment Risk

๐Ÿ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2025-12-05

Added to CISA KEV: 2025-12-08 3 DAYS BETWEEN CVE AND KEV

๐ŸŽฏ Recommendations:

๐Ÿ” Web Intelligence

Key Sources: