Skip to content
COOEY

FAIL › dossier

Array Networks

VENDOR

· dossier confidence 80%

Array Digital Infrastructure, a subsidiary of Telephone and Data Systems, operates a network of cell towers across the US. Recent security incidents involving remote code execution vulnerabilities in their ArrayOS platform highlight a need for improved security practices and patching processes.

PROFILE
CategoryWireless InfrastructureWhat they doArray Digital Infrastructure owns and operates shared wireless communications infrastructure in the United States, enabling the deployment of 5G and other wireless technologies. The company has over 4,400 cell towers and leases tower space to tenants.Founded1969HQChicago, ILOwnershipSubsidiary Websitehttps://investors.arrayinc.com/home/default.aspx ↗
SECURITY POSTURE

Array Networks has demonstrated significant vulnerabilities in its ArrayOS platform, resulting in actively exploited remote code execution vulnerabilities. These incidents indicate a need for improved security posture and processes.

Notable failures
  • CVE-2023-28461 (RCE) - Missing authentication vulnerability
  • CVE-2025-66644 (RCE) - OS Command Injection Vulnerability
  • Actively exploited RCE vulnerability
Patterns: Unpatched vulnerabilities leading to remote code execution; Lack of authentication controls
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2024-11-25 CVE-2023-28461 critical Array Networks AG/vxAG ArrayOS suffered a missing authentication vulnerability allowing attackers to read local files and execute code on the SSL VPN gateway.
2025-12-08 CVE-2025-66644 high ArrayOS AG OS Command Injection Vulnerability actively exploited
Open questions: What specific security awareness and training programs are in place? · What is the process for vulnerability identification and remediation? · What is the scope of the 82% ownership by Telephone and Data Systems?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-08 04:06:57.192238+00:00