CVE-2025-66644
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-12-05
Last updated on: 2025-12-10
Assigner: MITRE
Description
Description
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| arraynetworks | arrayos_ag | to 9.4.5.9 (exc) |
| arraynetworks | ag1000 | * |
| arraynetworks | ag1000t | * |
| arraynetworks | ag1000v5 | * |
| arraynetworks | ag1100 | * |
| arraynetworks | ag1100v5 | * |
| arraynetworks | ag1150 | * |
| arraynetworks | ag1200 | * |
| arraynetworks | ag1200v5 | * |
| arraynetworks | ag1500 | * |
| arraynetworks | ag1500fips | * |
| arraynetworks | ag1500v5 | * |
| arraynetworks | ag1600 | * |
| arraynetworks | ag1600v5 | * |
| arraynetworks | vxag | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-78 | The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. |