Executive brief
Array Networks ArrayOS AG, a secure gateway used for remote access and VPN services, contains a critical vulnerability that allows attackers to run unauthorized commands on the system. This flaw has been actively exploited in the wild to install web shells, which can give attackers permanent access to the corporate network and the ability to steal sensitive data. Organizations using these gateways should update to the latest firmware immediately to prevent unauthorized access and potential ransomware incidents.
Technical details
An OS command injection vulnerability (CWE-78) exists in Array Networks ArrayOS AG before version 9.4.5.9. The flaw stems from improper neutralization of special elements used in an OS command, allowing a remote attacker to execute arbitrary code with high privileges. While some assessments suggest high privileges are required, NIST has rated this as unauthenticated (PR:N) with a CVSS score of 9.8. The vulnerability has been actively exploited in the wild since August 2025 to deploy web shells on affected appliances. Users are advised to upgrade to version 9.4.5.9 or later.
Affected products
- Array Networks ArrayOS AG before 9.4.5.9
Timeline
- 2025-08: exploited: Earliest reported exploitation in the wild.
- 2025-12-05: disclosed: Initial CVE publication.
- 2025-12-08: kev added: Added to CISA Known Exploited Vulnerabilities catalog.