Description
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
Published: 2025-12-05
Score: 7.2 High
EPSS: 3.1% Low
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Dec 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Arraynetworks ag1000
Arraynetworks ag1000t
Arraynetworks ag1000v5
Arraynetworks ag1100
Arraynetworks ag1100v5
Arraynetworks ag1150
Arraynetworks ag1200
Arraynetworks ag1200v5
Arraynetworks ag1500
Arraynetworks ag1500fips
Arraynetworks ag1500v5
Arraynetworks ag1600
Arraynetworks ag1600v5
Arraynetworks vxag
CPEs cpe:2.3:h:arraynetworks:ag1000:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1000t:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1000v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1100:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1100v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1150:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1200:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1200v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1500:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1500fips:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1500v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1600:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:ag1600v5:-:*:*:*:*:*:*:*
cpe:2.3:h:arraynetworks:vxag:-:*:*:*:*:*:*:*
cpe:2.3:o:arraynetworks:arrayos_ag:*:*:*:*:*:*:*:*
Vendors & Products Arraynetworks ag1000
Arraynetworks ag1000t
Arraynetworks ag1000v5
Arraynetworks ag1100
Arraynetworks ag1100v5
Arraynetworks ag1150
Arraynetworks ag1200
Arraynetworks ag1200v5
Arraynetworks ag1500
Arraynetworks ag1500fips
Arraynetworks ag1500v5
Arraynetworks ag1600
Arraynetworks ag1600v5
Arraynetworks vxag

Tue, 09 Dec 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Arraynetworks
Arraynetworks arrayos Ag
Vendors & Products Arraynetworks
Arraynetworks arrayos Ag

Mon, 08 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 08 Dec 2025 18:30:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2025-12-08T00:00:00+00:00', 'dueDate': '2025-12-29T00:00:00+00:00'}


Mon, 08 Dec 2025 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 19:15:00 +0000


Fri, 05 Dec 2025 19:00:00 +0000

Type Values Removed Values Added
Description Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Arraynetworks Ag1000 Ag1000t Ag1000v5 Ag1100 Ag1100v5 Ag1150 Ag1200 Ag1200v5 Ag1500 Ag1500fips Ag1500v5 Ag1600 Ag1600v5 Arrayos Ag Vxag
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-02-26T16:57:31.054Z

Reserved: 2025-12-05T00:00:00.000Z

Link: CVE-2025-66644

cve-icon Vulnrichment

Updated: 2025-12-08T10:58:51.679Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-05T19:15:53.293

Modified: 2025-12-09T18:45:02.223

Link: CVE-2025-66644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-09T10:05:52Z

Weaknesses