Arraynetworks manufactures a narrow line of network security appliances, including models such as the AG1000 and VX AG series, that serve as critical chokepoints for enterprise network access and traffic filtering. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and have a strong, recurring history of confirmed in-the-wild exploitation, with the exposure concentrated in command-injection, authentication-bypass, and OS-command-injection weaknesses that reflect the appliance's privileged role in network defense. Defenders should prioritize remediation of this vendor's disclosures and restrict management access to these devices; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Arraynetworks over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28461CRITICAL Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in | Mar 15, 2023 | 9.8 | 92 | YES | NO |
CVE-2025-66644CRITICAL Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. | Dec 5, 2025 | 9.8 | 75 | YES | NO |
CVE-2022-42897CRITICAL Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x | Oct 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-51707CRITICAL MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffected. | Dec 22, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-41121HIGH Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations. | Aug 25, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-28460HIGH A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted packet after logging into the affected appliance as an adminis | Mar 15, 2023 | 7.2 | 19 | NO | NO |
CVE-2023-24613MEDIUM The user interface of Array Networks AG Series and vxAG through 9.4.0.470 could allow a remote attacker to use the gdb tool to overwrite the backend function call stack after acces | Feb 3, 2023 | 4.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Arraynetworks.
Media articles that mention a CVE ID that affects a product developed by Arraynetworks — matched by CVE ID, not by vendor name.