Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
History

Tue, 09 Dec 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Arraynetworks ag1000
Arraynetworks ag1000t
Arraynetworks ag1000v5
Arraynetworks ag1100
Arraynetworks ag1100v5
Arraynetworks ag1150
Arraynetworks ag1200
Arraynetworks ag1200v5
Arraynetworks ag1500
Arraynetworks ag1500fips
Arraynetworks ag1500v5
Arraynetworks ag1600
Arraynetworks ag1600v5
Arraynetworks vxag
CPEs cpe:2.3:h:arraynetworks:ag1000:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1000t:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1000v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1100:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1100v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1150:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1200:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1200v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1500:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1500fips:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1500v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1600:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1600v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:vxag:-:*:*:*:*:*:*:*
cpe:2.3:o:arraynetworks:arrayos_ag:*:*:*:*:*:*:*:*
Vendors & Products Arraynetworks ag1000
Arraynetworks ag1000t
Arraynetworks ag1000v5
Arraynetworks ag1100
Arraynetworks ag1100v5
Arraynetworks ag1150
Arraynetworks ag1200
Arraynetworks ag1200v5
Arraynetworks ag1500
Arraynetworks ag1500fips
Arraynetworks ag1500v5
Arraynetworks ag1600
Arraynetworks ag1600v5
Arraynetworks vxag

Tue, 09 Dec 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Arraynetworks
Arraynetworks arrayos Ag
Vendors & Products Arraynetworks
Arraynetworks arrayos Ag

Mon, 08 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 08 Dec 2025 18:30:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2025-12-08T00:00:00+00:00', 'dueDate': '2025-12-29T00:00:00+00:00'}


Mon, 08 Dec 2025 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 19:15:00 +0000


Fri, 05 Dec 2025 19:00:00 +0000

Type Values Removed Values Added
Description Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-12-05T00:00:00.000Z

Updated: 2025-12-09T04:55:52.076Z

Reserved: 2025-12-05T00:00:00.000Z

Link: CVE-2025-66644

cve-icon Vulnrichment

Updated: 2025-12-08T10:58:51.679Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-05T19:15:53.293

Modified: 2025-12-09T18:45:02.223

Link: CVE-2025-66644

cve-icon Redhat

No data.