ArrayOS 9.4.5.9 Cmd Inject CVE-2025-66644
CVE-2025-66644 Published on December 5, 2025

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

NVD

Known Exploited Vulnerability

This Array Networks ArrayOS AG OS Command Injection Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands.

The following remediation steps are recommended / required by December 29, 2025: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness Type

What is a Shell injection Vulnerability?

The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

CVE-2025-66644 has been classified to as a Shell injection vulnerability or weakness.


Affected Versions

Array Networks ArrayOS AG:

Exploit Probability

EPSS
3.20%
Percentile
87.02%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.