A recent command injection vulnerability in Array Networks AG Series gateways has been actively exploited in Japan since August 2025, allowing attackers to implant web shells and access internal systems. Although a fix was released in May 2025, many devices remain unpatched, creating a significant security risk. #ArrayNetworks #WebShells
Keypoints
- An active exploitation of a command injection flaw affects Array Networks AG Series gateways in Japan.
- The vulnerability originates in the DesktopDirect remote access feature, which was patched in May 2025 but remains unpatched on some devices.
- Attackers have targeted organizations since August 2025 by planting PHP web shells through malicious web requests.
- Malicious traffic originates from IP address 194.233.100[.]138], but threat actor details are unknown.
- Array Networks released a firmware update (ArrayOS 9.4.5.9) to fix the vulnerability, with recommendations for immediate deployment and incident monitoring.
Read More: https://thecyberexpress.com/cve-2023-28461-jpcert-array-gateway-warning/