Active Exploitation of Command Injection Flaw Confirmed in Array AG Gateways

Active Exploitation of Command Injection Flaw Confirmed in Array AG Gateways

A recent command injection vulnerability in Array Networks AG Series gateways has been actively exploited in Japan since August 2025, allowing attackers to implant web shells and access internal systems. Although a fix was released in May 2025, many devices remain unpatched, creating a significant security risk. #ArrayNetworks #WebShells

Keypoints

  • An active exploitation of a command injection flaw affects Array Networks AG Series gateways in Japan.
  • The vulnerability originates in the DesktopDirect remote access feature, which was patched in May 2025 but remains unpatched on some devices.
  • Attackers have targeted organizations since August 2025 by planting PHP web shells through malicious web requests.
  • Malicious traffic originates from IP address 194.233.100[.]138], but threat actor details are unknown.
  • Array Networks released a firmware update (ArrayOS 9.4.5.9) to fix the vulnerability, with recommendations for immediate deployment and incident monitoring.

Read More: https://thecyberexpress.com/cve-2023-28461-jpcert-array-gateway-warning/