Motex has disclosed a serious remote code execution vulnerability in LANSCOPE Endpoint Manager On-Premise. Labeled CVE-2025-61932, the flaw carries a CVSS 3.0 score of 9.8, ranking it as Critical. This vulnerability could allow attackers to execute arbitrary code on affected systems, potentially leading to a complete compromise of endpoint devices.
See also: ZYXEL vulnerability allows bypass of authorization checks

The problem is located in the product's Client Program (MR) and Detection Agent (DA), components responsible for managing and monitoring endpoint security.
According to Motex's announcement, versions up to 9.4.7.1 are vulnerable. Importantly, the cloud-based version remains unaffected, sparing users of the SaaS version from immediate risk. However, on-premise deployment, popular among organizations seeking greater control over their IT environments, is now facing urgent scrutiny.
What triggers the alarm is evidence of active exploitation. Motex reports have confirmed cases where customer environments have received malicious packets from external sources. The attackers appear to be targeting client-side programs remotely, exploiting vulnerabilities that bypass typical network defenses.
Security researchers speculate that this could be due to improper input validation in detection and management protocols, although the full technical details await independent analysis.
See also: Dolby Digital Plus: Vulnerability allows RCE attack

This vulnerability highlights broader risks in endpoint management tools, which often run with elevated privileges. Once exploited, attackers could deploy malware, steal sensitive data, or delve deeper into corporate networks.
Given the high CVSS score due to network accessibility, low complexity, and lack of user permissions or interaction, organizations using affected versions should prioritize remediation.
Motex has immediately released a fix, accessible through the customer support portal, LANSCOPE PORTAL. The update is targeted exclusively at client computers. The central administrator does not require an upgrade.
The deployment follows standard procedures, making it easy for IT teams to deploy the application to all endpoints. As of August 2025, when the advisory was issued, there have been no publicly reported widespread breaches associated with this CVE, but the confirmed malicious activity signals the potential for rapid escalation.
See also: PoC exploit released for Windows Server Update Services vulnerability

Cyber experts are urging immediate patching to mitigate risks, especially in hybrid work settings where endpoints are connected remotely.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
