CVE-2025-66644

Published Dec 5, 2025

Last updated 3 months ago

Overview

Description
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
Source
cve@mitre.org
NVD status
Analyzed
Products
arrayos_ag

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cve@mitre.org
CWE-78

Social media

Hype score
Not currently trending
  1. SECURITY ALERT: CVE-2025-66644 Exploit Fix & Mitigation Guide Read more: https://t.co/a7hddOkizL #Cybersecurity #CVE https://t.co/YcsZZupUpJ

    @SecReportCVE

    1 Jan 2026

    61 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2025-66644 Array Networks ArrayOS AG OS Command Injection Vulnerability https://t.co/cZddxXtI0W

    @ScyScan

    22 Dec 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. IPAのArray Networks製Array AGシリーズにおけるコマンドインジェクションの脆弱性について(※CVE-2025-66644になった)のページをリロードしたら、悪性IPリストが減っててビックリしたw https://t.co/medvT0M9Jj https://t.co/G1

    @seen8th

    9 Dec 2025

    167 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨🚨CVE-2025-66644: Array Networks ArrayOS AG OS Command Injection Vulnerability Search by vul.cve Filter👉vul.cve="CVE-2025-66644" ZoomEye Dork👉app="Array Networks ArrayOS" 19.9k+ exposed instances. ZoomEye Link: https://t.co/PeacwBOfxc Refer: 1. https://t.co/CTHVLZw

    @zoomeye_team

    9 Dec 2025

    1952 Impressions

    5 Retweets

    25 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-66644 Array Networks Array AGシリーズにおけるコマンドインジェクションの脆弱性に関する注意喚起 https://t.co/zRNxMa55nf Array Networks製Array AGシリーズにおけるコマンドインジェクションの脆弱性について https://t

    @taku888infinity

    9 Dec 2025

    789 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  6. 🛡️We added D-Link routers and Array Networks vulnerabilities CVE-2022-37055 & CVE-2025-66644 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/

    @CISACyber

    8 Dec 2025

    6635 Impressions

    28 Retweets

    58 Likes

    9 Bookmarks

    3 Replies

    0 Quotes

  7. CVE-2025-66644 Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. https://t.co/jzbtdnic5e

    @CVEnew

    5 Dec 2025

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations