CVE-2025-66644
9.5 CISA KEVArray Networks · ArrayOS AG
Array Networks ArrayOS AG before 9.4.5.9 is susceptible to OS Command Injection, allowing an authenticated attacker with high privileges to execute arbitrary system commands.
Executive summary
A critical OS command injection vulnerability in Array Networks ArrayOS AG is currently being exploited in the wild to plant persistent webshells on affected systems.
Vulnerability
This vulnerability, classified as CWE-78, allows an attacker with high privileges to inject and execute arbitrary OS commands. The flaw facilitates unauthorized system access and the deployment of persistent backdoors.
Business impact
The severity of this vulnerability is underscored by its CVSS score of 9.5 and its confirmed status in the CISA Known Exploited Vulnerabilities catalog. Successful exploitation grants an attacker full control over the affected appliance, leading to total compromise of confidentiality, integrity, and availability. This risk is compounded by the observed deployment of webshells, which can lead to long-term unauthorized access to internal network infrastructure and sensitive data.
Remediation
Immediate Action: Update ArrayOS AG to version 9.4.5.9 or later immediately to resolve the command injection flaw.
Proactive Monitoring: Inspect system logs for unusual process execution or unauthorized modifications, and monitor for the presence of unexpected files or webshells on the appliance filesystem.
Compensating Controls: Ensure the management interface of the ArrayOS AG device is restricted to trusted internal networks or VPNs to prevent unauthorized access by high-privileged accounts.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists via GitHub (Ashwesker/Blackash-CVE-2025-66644).
Analyst recommendation
Given the critical nature of this vulnerability and the confirmed evidence of active exploitation, organizations must prioritize patching ArrayOS AG to version 9.4.5.9 or later. The presence of public proof-of-concept code and the documented use of this exploit to install backdoors make this a high-priority security event that requires immediate attention from IT and security operations teams.