top of page
perceptive_background_267k.jpg

Hackers are exploiting ArrayOS AG VPN flaw to plant webshells

Published:

4 December 2025 at 23:05:05

Alert date:

5 December 2025 at 08:03:22

Source:

bleepingcomputer.com

Click to open the original link from this advisory

Threat actors are actively exploiting a command injection vulnerability in Array AG Series VPN devices to deploy webshells and create unauthorized user accounts. The attacks involve planting malicious webshells that provide persistent access to compromised VPN infrastructure. Attackers are using this access to establish rogue user accounts for continued access. The vulnerability affects Array AG Series VPN appliances and is being actively exploited in the wild. Organizations using these devices should take immediate action to secure their systems.

Technical details

Mitigation steps:

Affected products:

Array AG Series VPN
ArrayOS AG

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page