Exploitation of Array Networks AG Series Command Injection Vulnerability Confirmed

Exploitation of Array Networks AG Series Command Injection Vulnerability Confirmed

First seen 16 Dec 2025, 22:57 UTC ThecyberexpressScworld 56.1

Article Content

Browse articles
ThreatCluster

A command injection vulnerability in Array Networks AG Series secure access gateways, tracked as CVE-2025-66644, has been actively exploited since August 2025. The flaw affects the DesktopDirect remote access solution, allowing attackers to execute arbitrary commands and implant web shells for unauthorized access. The Japan Computer Emergency Response Team (JPCERT/CC) issued an advisory on December 5, 2025, confirming the ongoing exploitation in Japan.