{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2025-66644",
  "revision": 1,
  "title": "Array Networks ArrayOS — command injection on the gateway",
  "summary": "Array Networks ArrayOS before 9.4.5.9 lets an attacker inject commands and run them on the remote access gateway. Attackers used it from August through December 2025 to plant web shells.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.03415,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2025-12-08",
    "prerequisites": "Network access to the gateway; no credentials needed."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "ArrayOS AG 9.4.5.9"
    ]
  },
  "mitre_attack": [
    "T1059"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Upgrade ArrayOS to 9.4.5.9 or later now; it was exploited for months to plant web shells, so sweep the appliance before trusting it again.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-66644",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2025-66644",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-66644",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-66644",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "writeup",
      "url": "https://www.jpcert.or.jp/at/2025/at250024.html"
    },
    {
      "type": "writeup",
      "url": "https://x.com/ArraySupport/status/1921373397533032590"
    }
  ],
  "published_at": "2025-12-05T19:15:53.293Z",
  "issued_at": "2026-09-24T08:51:39.744Z",
  "tags": [
    "array-networks",
    "arrayos",
    "vpn",
    "command-injection",
    "webshell",
    "kev"
  ]
}
