ArrayOS AG VPN Vulnerability Actively Targeted by Hackers to Deploy Webshells

A recently disclosed command injection vulnerability in the DesktopDirect function of Array Networks’ ArrayOS AG series has come under active exploitation, according to a new advisory from JPCERT/CC.

The flaw affects ArrayOS AG version 9.4.5.8 and earlier, allowing remote attackers to execute arbitrary commands on vulnerable devices.

DesktopDirect, which provides remote desktop access, is a built-in feature of the AG VPN appliances used widely in corporate environments.

The vulnerability enables attackers to send crafted requests that can bypass standard authentication and inject commands into the system, resulting in unauthorized control over the appliance.

Array Networks addressed the issue in May 2025 with the release of ArrayOS AG version 9.4.5.9, although no CVE number has yet been assigned to the flaw.

Despite the patch being available for several months, JPCERT/CC has confirmed that targeting of unpatched systems began in August 2025, mainly affecting organizations in Japan.

Attackers have successfully exploited the vulnerability to install PHP-based webshells, create unauthorized user accounts, and infiltrate internal networks through compromised AG VPN devices.

Logs indicate that attempts to install webshells were found in paths containing “/webapp/,” suggesting exploitation through the system’s web interface.

Activity associated with the attack has been traced to the IP address 194.233.100[.]138, which has been identified as the source of malicious traffic.

Ongoing Exploitation and Mitigation Measures

Array Networks and JPCERT/CC are advising all users of the ArrayOS AG series to verify whether their systems are running affected versions urgently and to apply the security update after appropriate testing.

Administrators should preserve existing log data before rebooting the product to prevent loss of forensic evidence, since a system restart following the update may erase stored logs.

During investigations, organizations should carefully inspect directories and user accounts for signs of intrusion, especially files with PHP extensions created under web application paths.

For environments unable to immediately install the fixed version, Array Networks suggests turning off the DesktopDirect service entirely if it is not in use, or applying URL filtering to reject requests that contain semicolons, which attackers can leverage for command injection.

The company’s official support communication confirms that version 9.4.5.9 for the Array AG 1000 series and other affected models is now available for download.

Given the confirmed exploitation and potential for privilege escalation, JPCERT/CC strongly recommends patching, conducting comprehensive intrusion analysis, and monitoring network traffic for anomalies related to DesktopDirect request activity.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

Priya
Priya
Priya is a Security Reporter who tracks malware campaigns, exploit kits, and ransomware operations. Her reporting highlights technical indicators and attack patterns that matter to defenders

Trending News

Related Stories