Vulnerability record · CVE-2025-61932 · published 20 October 2025
CVE-2025-61932: Lanscope Endpoint Manager improper origin verification allows RCE
Motex · Lanscope Endpoint Manager
Lanscope Endpoint Manager (On-Premises), in both the Client program (MR) and Detection agent (DA), does not properly verify the origin of incoming requests. An attacker can send specially crafted packets to trigger arbitrary code execution. The flaw is remotely reachable without authentication or user interaction and is listed in CISA KEV, so it warrants urgent attention.
Description
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCVSS 4.0 base score is 9.3 with no privileges or user interaction required, and the CVE is in CISA KEV with a 2025-11-12 remediation deadline.
What it is
Lanscope Endpoint Manager (On-Premises), in both the Client program (MR) and Detection agent (DA), does not properly verify the origin of incoming requests. An attacker can send specially crafted packets to trigger arbitrary code execution. The flaw is remotely reachable without authentication or user interaction and is listed in CISA KEV, so it warrants urgent attention.
Impact
An unauthenticated attacker can execute arbitrary code on affected endpoints or servers, giving full control of the compromised component and a foothold for lateral movement.
Attack surface
Reachable over the network via crafted packets to the MR client program and DA detection agent; the CVSS 4.0 vector shows no privileges or user interaction required. No further detail on the specific port or protocol is provided in the record.
Exploitation
CVE-2025-61932 was added to CISA KEV on 2025-10-22 with a remediation due date of 2025-11-12, indicating known exploitation; EPSS 30-day probability is 0.02628 (84.7th percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor fix from the Motex advisory (release251020) as the first action; confirm the patched MR and DA versions.
- If patching is not immediately possible, restrict network access to the MR client program and DA detection agent to trusted management hosts only.
- Follow CISA BOD 22-01 guidance and the KEV required action; discontinue use of the product if mitigations are unavailable.
- Monitor vendor and JVN advisories for updated guidance and interim workarounds.
- Inventory all on-premises Lanscope Endpoint Manager deployments, including MR and DA components, to ensure none are missed.
Detection
- Hunt for unexpected or malformed packets reaching MR and DA listeners from non-management hosts.
- Review endpoint and server logs for process creation or code execution originating from the Lanscope MR/DA service context.
- Alert on new outbound connections or child processes spawned by Lanscope components.
- Correlate network telemetry for anomalous traffic to Lanscope management ports with host-based execution events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-61932 to the Known Exploited Vulnerabilities catalog on 22 October 2025 as "Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 November 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jvn.jp/en/jp/JVN86318557/ | Third Party Advisory |
| https://www.motex.co.jp/news/notice/2025/release251020/ | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61932 | Third Party AdvisoryUS Government Resource |
Track CVE-2025-61932 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-61932), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.