← Vulnerability feed

Vulnerability record · CVE-2025-61932 · published 20 October 2025

CVE-2025-61932: Lanscope Endpoint Manager improper origin verification allows RCE

Motex · Lanscope Endpoint Manager

Lanscope Endpoint Manager (On-Premises), in both the Client program (MR) and Detection agent (DA), does not properly verify the origin of incoming requests. An attacker can send specially crafted packets to trigger arbitrary code execution. The flaw is remotely reachable without authentication or user interaction and is listed in CISA KEV, so it warrants urgent attention.

9.3 CVSS 4.0 Critical CISA KEV since 22 Oct 2025 EPSS 2.8% · top 14.3% CWE-940 · CWE-940
9.3CVSS 4.0 base score
2.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 4.0 base score is 9.3 with no privileges or user interaction required, and the CVE is in CISA KEV with a 2025-11-12 remediation deadline.

What it is

Lanscope Endpoint Manager (On-Premises), in both the Client program (MR) and Detection agent (DA), does not properly verify the origin of incoming requests. An attacker can send specially crafted packets to trigger arbitrary code execution. The flaw is remotely reachable without authentication or user interaction and is listed in CISA KEV, so it warrants urgent attention.

Impact

An unauthenticated attacker can execute arbitrary code on affected endpoints or servers, giving full control of the compromised component and a foothold for lateral movement.

Attack surface

Reachable over the network via crafted packets to the MR client program and DA detection agent; the CVSS 4.0 vector shows no privileges or user interaction required. No further detail on the specific port or protocol is provided in the record.

Exploitation

CVE-2025-61932 was added to CISA KEV on 2025-10-22 with a remediation due date of 2025-11-12, indicating known exploitation; EPSS 30-day probability is 0.02628 (84.7th percentile). No ransomware campaign use is documented.

What to do

  • Apply the vendor fix from the Motex advisory (release251020) as the first action; confirm the patched MR and DA versions.
  • If patching is not immediately possible, restrict network access to the MR client program and DA detection agent to trusted management hosts only.
  • Follow CISA BOD 22-01 guidance and the KEV required action; discontinue use of the product if mitigations are unavailable.
  • Monitor vendor and JVN advisories for updated guidance and interim workarounds.
  • Inventory all on-premises Lanscope Endpoint Manager deployments, including MR and DA components, to ensure none are missed.

Detection

  • Hunt for unexpected or malformed packets reaching MR and DA listeners from non-management hosts.
  • Review endpoint and server logs for process creation or code execution originating from the Lanscope MR/DA service context.
  • Alert on new outbound connections or child processes spawned by Lanscope components.
  • Correlate network telemetry for anomalous traffic to Lanscope management ports with host-based execution events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-61932 to the Known Exploited Vulnerabilities catalog on 22 October 2025 as "Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 November 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-61932 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2025-61932), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.