


Perceptive Security
SOC/SIEM Consultancy

JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
Published:
5 December 2025 at 05:40:00
Alert date:
5 December 2025 at 08:03:22
Source:
thehackernews.com

JPCERT/CC has confirmed active exploitation of a command injection vulnerability in Array Networks AG Series secure access gateways since August 2025. The vulnerability affects the DesktopDirect remote desktop access solution and was patched by Array Networks on May 11, 2025. However, the vulnerability does not have a CVE identifier assigned. The flaw allows attackers to execute arbitrary commands on vulnerable systems, making it a high-priority security concern for organizations using these gateways.
Technical details
Mitigation steps:
Affected products:
Array Networks AG Series
DesktopDirect
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.