CVE-2025-61932: Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability

Critical severity, CVSS 9.3. Actively exploited: in CISA KEV since 2025-10-22. EPSS: 2.8% chance of exploitation in the next 30 days.

Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.

Affected products

  • Motex LANSCOPE Endpoint Manager: before 9.3.2.7 (fixed in 9.3.2.7); from 9.3.3.0, before 9.3.3.9 (fixed in 9.3.3.9); from 9.4.0.0, before 9.4.0.5 (fixed in 9.4.0.5); from 9.4.1.0, before 9.4.1.5 (fixed in 9.4.1.5); from 9.4.2.0, before 9.4.2.6 (fixed in 9.4.2.6); from 9.4.3.0, before 9.4.3.8 (fixed in 9.4.3.8); …

Published 2025-10-20. Last modified 2026-10-08.