


Perceptive Security
SOC/SIEM Consultancy

Hackers are exploiting ArrayOS AG VPN flaw to plant webshells
Published:
4 December 2025 at 23:05:05
Alert date:
5 December 2025 at 08:03:22
Source:
bleepingcomputer.com

Threat actors are actively exploiting a command injection vulnerability in Array AG Series VPN devices to deploy webshells and create unauthorized user accounts. The attacks involve planting malicious webshells that provide persistent access to compromised VPN infrastructure. Attackers are using this access to establish rogue user accounts for continued access. The vulnerability affects Array AG Series VPN appliances and is being actively exploited in the wild. Organizations using these devices should take immediate action to secure their systems.
Technical details
Mitigation steps:
Affected products:
Array AG Series VPN
ArrayOS AG
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.