๐Ÿ”ด CVE-2025-66644

Critical OS command injection vulnerability in Array Networks ArrayOS AG VPN appliances affecting versions before 9.4.5.9. Active exploitation confirmed in the wild from August-December 2025 with attackers deploying webshells for persistent access.

โ† Back to Overview
HIGH_RISK
Risk Level
7.2
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 โ€” Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

๐Ÿ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2025-12-05

Added to CISA KEV: 2025-12-08 3 DAYS BETWEEN CVE AND KEV

๐ŸŽฏ Recommendations:

๐Ÿ” Web Intelligence (Kagi ยท 2025-12-08)

Here's what is known about the CVE-2025-66644 vulnerability:

Summary:
  • CVE-2025-66644 affects Array Networks ArrayOS AG versions before 9.4.5.9 and involves a command injection vulnerability [1][2].
  • It has been exploited in the wild between August and December 2025 [1][2].
Specifics:
  • Affected Applications/Services: Array Networks ArrayOS AG. The vulnerability potentially affects internet-facing applications or services due to the nature of command injection vulnerabilities in network appliances [1].
  • Exploitation: There is evidence of active exploitation in the wild between August and December 2025 [1][2].
  • Attack Vectors/Exploitation Methods: The vulnerability is a command injection, meaning an attacker can inject arbitrary commands into the system [1].
  • Targeted Attacks: While it's confirmed that the vulnerability has been actively exploited, there is no specific information available confirming if these exploits were used in targeted attacks.
  • CISA Known Exploited Vulnerabilities Status: A CISA bulletin mentions CVE-2025-66644 [3].
  • Internet Exploitability: The command injection vulnerability in ArrayOS AG suggests it is internet exploitable, especially if the affected devices are exposed to the internet [1].
Caveats:
  • The information available is limited, but it does confirm active exploitation of a command injection vulnerability in Array Networks ArrayOS AG.

Sources

  1. CVE-2025-66644 Security Vulnerability & Exploit Details

    CVE-2025-66644: Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

  2. CVE-2025-66577 Security Vulnerability & Exploit Details

    CVE-2025-66577 Vulnerability Analysis & Exploit Details.Join the top cybersecurity professionals safeguarding today's infrastructures. Other 5 Recently Published CVEs Vulnerabilities. CVE-2025-66644 โ€“ Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in Auguโ€ฆ

  3. Vulnerability Summary for the Week of December 1, 2025

    Vulnerabilities are based on the Common Vulnerabilities and Exposures (CVE) vulnerability ... CVE-2025-66644 ยท https://www.jpcert.or.jp/at/2025/ ...