top of page
perceptive_background_267k.jpg

JPCERT Confirms Active Command Injection Attacks on Array AG Gateways

Published:

5 december 2025 om 05:40:00

Alert date:

5 december 2025 om 08:03:22

Source:

thehackernews.com

Click to open the original link from this advisory

JPCERT/CC has confirmed active exploitation of a command injection vulnerability in Array Networks AG Series secure access gateways since August 2025. The vulnerability affects the DesktopDirect remote desktop access solution and was patched by Array Networks on May 11, 2025. However, the vulnerability does not have a CVE identifier assigned. The flaw allows attackers to execute arbitrary commands on vulnerable systems, making it a high-priority security concern for organizations using these gateways.

Technical details

Mitigation steps:

Affected products:

Array Networks AG Series
DesktopDirect

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page