JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内。用户已经给出了文章的详细内容,我需要先仔细阅读并理解文章的主要信息。 首先,文章提到Array Networks AG系列的安全网关存在一个命令注入漏洞,这个漏洞从2025年8月开始被利用。JPCERT/CC发布了这个警报。漏洞影响的是DesktopDirect功能,该功能允许远程访问。攻击者可以执行任意命令,并且已经有日本的案例被确认,攻击者利用此漏洞植入网络壳。 此外,文章还提到该产品之前有一个认证绕过漏洞被中国相关的网络间谍组织利用,但目前没有证据表明这次攻击与该组织有关。建议用户升级到最新版本或禁用相关服务。 现在我需要将这些信息浓缩到100字以内。重点包括:漏洞名称、影响范围、攻击情况、建议措施等。 可能的结构是:Array Networks AG系列的命令注入漏洞被利用,影响DesktopDirect功能,导致远程执行命令;日本已出现攻击案例;建议升级或禁用服务以缓解风险。 检查字数是否在限制内,并确保信息准确全面。 </think> Array Networks AG系列安全网关存在命令注入漏洞,影响DesktopDirect远程访问功能。自2025年8月起被利用,在日本植入网络壳。建议升级至ArrayOS 9.4.5.9或禁用服务以缓解风险。 2025-12-5 05:40:0 Author: thehackernews.com(查看原文) 阅读量:6 收藏

Vulnerability / Network Security

Command Injection Attacks on Array AG Gateways

A command injection vulnerability in Array Networks AG Series secure access gateways has been exploited in the wild since August 2025, according to an alert issued by JPCERT/CC this week.

The vulnerability, which does not have a CVE identifier, was addressed by the company on May 11, 2025. It's rooted in Array's DesktopDirect, a remote desktop access solution that allows users to securely access their work computers from any location.

"Exploitation of this vulnerability could allow attackers to execute arbitrary commands," JPCERT/CC said. "This vulnerability affects systems where the 'DesktopDirect' feature, which provides remote desktop access, is enabled."

The agency said it has confirmed incidents in Japan that have exploited the shortcoming after August 2025 to drop web shells on susceptible devices. The attacks have originated from the IP address "194.233.100[.]138."

Cybersecurity

There are currently no details available on the scale of the attacks, weaponizing the flaw, and identity of the threat actors exploiting it.

However, an authentication bypass flaw in the same product (CVE-2023-28461, 9.8) was exploited last year by a China-linked cyber espionage group dubbed MirrorFace, which has a history of targeting Japanese organizations since at least 2019. That said, there is no evidence to suggest that at this stage the threat actor could be linked to the latest attack spree.

The vulnerability impacts ArrayOS versions 9.4.5.8 and earlier, and has been addressed in version ArrayOS 9.4.5.9. Users are advised to apply the latest updates as soon as possible to mitigate potential threats. In case patching is not an immediate option, it's recommended to disable DesktopDirect services and use URL filtering to deny access to URLs containing a semicolon, JPCERT/CC said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2025/12/jpcert-confirms-active-command.html
如有侵权请联系:admin#unsafe.sh