CVE-2025-66644CRITICAL 9.8CISA KEVEPSS p85.8%

CVE-2025-66644Array Networks ArrayOS AG OS Command Injection Vulnerability

Array Networks / ArrayOS AG

Description

Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.05% probability of exploitation · percentile 85.8% · 2026-06-19T12:03:05Z
Published2025-12-05
Last modified2025-12-10

CISA KEV entry

Added to KEV: 2025-12-08

Underlying weaknesses· 1

CWE-78

References

  1. https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-arrayos-ag-vpn-flaw-to-plant-webshells/
  2. https://www.jpcert.or.jp/at/2025/at250024.html
  3. https://x.com/ArraySupport/status/1921373397533032590
  4. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66644

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')cwe-780%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryArray Networks ArrayOS AG OS Command Injection Vulnerabilitykev-cve-2025-666440%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-44866
CVE
CVE-2026-4620
CVE
CVE-2026-44867
CVE
CVE-2026-44868
CVE
CVE-2026-44869
CVE
CVE-2026-23814
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.