{"id":"CVE-2025-66644","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-66644","summary":"Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.","details":"Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.","published":"2025-12-05T00:00:00.000Z","modified":"2026-02-26T16:57:31.054Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.03462,"percentile":0.88133,"asOf":"2026-08-24"},"cisaKev":{"dateAdded":"2025-12-08","dueDate":"2025-12-29","knownRansomwareCampaignUse":false},"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.jpcert.or.jp/at/2025/at250024.html"},{"type":"WEB","url":"https://x.com/ArraySupport/status/1921373397533032590"},{"type":"WEB","url":"https://www.bleepingcomputer.com/news/security/hackers-are-exploiting-arrayos-ag-vpn-flaw-to-plant-webshells/"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-66644"}],"provenance":{"sources":["OSV.dev","NVD","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2026-02-26T16:57:31.054Z"}}