- Description
- Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
- Source
- cve@mitre.org
- NVD status
- Analyzed
- Products
- arrayos_ag
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- cve@mitre.org
- CWE-78
- Hype score
- Not currently trending
SECURITY ALERT: CVE-2025-66644 Exploit Fix & Mitigation Guide Read more: https://t.co/a7hddOkizL #Cybersecurity #CVE https://t.co/YcsZZupUpJ
@SecReportCVE
1 Jan 2026
61 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2025-66644 Array Networks ArrayOS AG OS Command Injection Vulnerability https://t.co/cZddxXtI0W
@ScyScan
22 Dec 2025
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
IPAのArray Networks製Array AGシリーズにおけるコマンドインジェクションの脆弱性について(※CVE-2025-66644になった)のページをリロードしたら、悪性IPリストが減っててビックリしたw https://t.co/medvT0M9Jj https://t.co/G1
@seen8th
9 Dec 2025
167 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨🚨CVE-2025-66644: Array Networks ArrayOS AG OS Command Injection Vulnerability Search by vul.cve Filter👉vul.cve="CVE-2025-66644" ZoomEye Dork👉app="Array Networks ArrayOS" 19.9k+ exposed instances. ZoomEye Link: https://t.co/PeacwBOfxc Refer: 1. https://t.co/CTHVLZw
@zoomeye_team
9 Dec 2025
1952 Impressions
5 Retweets
25 Likes
4 Bookmarks
0 Replies
0 Quotes
CVE-2025-66644 Array Networks Array AGシリーズにおけるコマンドインジェクションの脆弱性に関する注意喚起 https://t.co/zRNxMa55nf Array Networks製Array AGシリーズにおけるコマンドインジェクションの脆弱性について https://t
@taku888infinity
9 Dec 2025
789 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
🛡️We added D-Link routers and Array Networks vulnerabilities CVE-2022-37055 & CVE-2025-66644 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/
@CISACyber
8 Dec 2025
6635 Impressions
28 Retweets
58 Likes
9 Bookmarks
3 Replies
0 Quotes
CVE-2025-66644 Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. https://t.co/jzbtdnic5e
@CVEnew
5 Dec 2025
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arraynetworks:arrayos_ag:*:*:*:*:*:*:*:*",
"matchCriteriaId": "10896125-DBC8-46DD-8F4E-C6A9A9ED7D16",
"versionEndExcluding": "9.4.5.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:arraynetworks:ag1000:-:*:*:*:*:*:*:*",
"matchCriteriaId": "EBE11A77-8C2F-46CA-87BA-47624380FFC1",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:arraynetworks:ag1000t:-:*:*:*:*:*:*:*",
"matchCriteriaId": "5ED51E1F-3155-40C6-B61C-73D6A9F64987",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:arraynetworks:ag1000v5:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F0BC33CF-FA0B-4556-B11E-61FF9B14880A",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:arraynetworks:ag1100:-:*:*:*:*:*:*:*",
"matchCriteriaId": "CD94C3C7-FA86-47EC-8D5C-4805CC9D7739",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:arraynetworks:ag1100v5:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A9C8C9AE-AF59-4E5A-93CD-A394F1A31FA0",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:arraynetworks:ag1150:-:*:*:*:*:*:*:*",
"matchCriteriaId": "5E025A9D-6B7C-42B6-95EA-0A5726A919F4",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:arraynetworks:ag1200:-:*:*:*:*:*:*:*",
"matchCriteriaId": "0771D54C-15DF-403C-8CFA-B1E7D0136F50",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:arraynetworks:ag1200v5:-:*:*:*:*:*:*:*",
"matchCriteriaId": "7C9F6B87-E3D2-419A-B086-B981EF912F80",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:arraynetworks:ag1500:-:*:*:*:*:*:*:*",
"matchCriteriaId": "D385DBD0-C4A9-4168-82C2-832E0E40F42D",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:arraynetworks:ag1500fips:-:*:*:*:*:*:*:*",
"matchCriteriaId": "01569AB3-736D-47FE-86DD-F08ACDDCD11E",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:arraynetworks:ag1500v5:-:*:*:*:*:*:*:*",
"matchCriteriaId": "22E45185-071F-414A-AF78-4739F15A1D93",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:arraynetworks:ag1600:-:*:*:*:*:*:*:*",
"matchCriteriaId": "C6F0988E-5E75-486A-9229-956D38A51C35",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:arraynetworks:ag1600v5:-:*:*:*:*:*:*:*",
"matchCriteriaId": "1D09E2CC-C1B5-40DC-AD1A-7C6AB20525DC",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:arraynetworks:vxag:-:*:*:*:*:*:*:*",
"matchCriteriaId": "6E149796-E3D7-4FAF-AB64-8D273E701861",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]