Array Networks Product Security Update Advisory (CVE-2025-66644)

Array Networks Product Security Update Advisory (CVE-2025-66644)

Overview

 

Array Networks has released a security update to fix vulnerabilities in Array Networks products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-66644

 

ArrayOS AG Version: 9.4.5.8 and earlier

 

 

Resolved Vulnerabilities

 

Command injection vulnerability in the DesktopDirect feature in Array AG (CVE-2025-66644)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2025-66644

 

ArrayOS AG Version: 9.4.5.9

 

 

References

 

[1] Array Support
https://x.com/ArraySupport/status/1921373397533032590
[2] Array Networks Array AG Series Caution regarding the vulnerability of compandintegration on Array AG Series
https://www.jpcert.or.jp/at/2025/at250024.html