Skip to content

CVE-2023-28461

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
December 4, 2025
Last Seen
December 5, 2025
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A command injection vulnerability in Array Networks AG Series secure access gateways, tracked as CVE-2025-66644, has been actively exploited since August 2025. The flaw affects the DesktopDirect remote access solution, allowing attackers to execute arbitrary commands and implant web shells for unaut...

Threat actors are exploiting a command injection vulnerability in ArrayOS AG VPN devices to deploy webshells and create unauthorized user accounts. The vulnerability has been actively targeted since at least August 2025, affecting various organizations. Array Networks issued a security update in May...

Public Exploits

Checking GitHub for proof-of-concept code…