Exploit for CVE-2023-28461

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."

Published: 2023-03-15

CVSS: 9.8

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Download Exploit for CVE-2023-28461 here:

Use Tor Browser to access .onion links.

Check our team here:

https://tatramed.sk/exploit-628-cve-2025-43272/

https://tatramed.sk/exploit-237-cve-2017-1000486/

https://tatramed.sk/exploit-229-cve-2022-0952/