PT-2025-49310 · Array Networks · Array Ag Os
Published
2025-08-20
·
Updated
2026-01-01
·
CVE-2025-66644
CVSS v2.0
10
Critical
| AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Array Networks ArrayOS AG versions prior to 9.4.5.9
Description
Array Networks ArrayOS AG before version 9.4.5.9 contains a command injection flaw. This issue has been exploited in the wild, specifically between August and December 2025, including instances in Japan where it was used to deploy PHP webshells. Approximately 19,900 instances are potentially exposed. The flaw allows for arbitrary code execution. The vulnerability involves the injection of commands into the system.
Recommendations
Versions prior to 9.4.5.9 should be updated to version 9.4.5.9 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Array Ag Os