Critical OS command injection vulnerability in Array Networks ArrayOS AG VPN appliances affecting versions before 9.4.5.9. Active exploitation confirmed in the wild from August-December 2025 with attackers deploying webshells for persistent access.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-12-05
Added to CISA KEV: 2025-12-08 3 DAYS BETWEEN CVE AND KEV
Here's what is known about the CVE-2025-66644 vulnerability:
Summary:CVE-2025-66644: Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
CVE-2025-66577 Vulnerability Analysis & Exploit Details.Join the top cybersecurity professionals safeguarding today's infrastructures. Other 5 Recently Published CVEs Vulnerabilities. CVE-2025-66644 โ Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in Auguโฆ
Vulnerabilities are based on the Common Vulnerabilities and Exposures (CVE) vulnerability ... CVE-2025-66644 ยท https://www.jpcert.or.jp/at/2025/ ...