HomeSecurityVulnerability in Lanscope Endpoint Manager allows cyberattacks

Vulnerability in Lanscope Endpoint Manager allows cyberattacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security vulnerability affecting Motex Lanscope Endpoint Manager to its list of Known Exploitable Vulnerabilities (KEV), stating that it has been actively exploited in real-world attacks.

See also: TARmageddon vulnerability in Rust's Async-Tar library allows remote code execution

Lanscope Endpoint Manager

The vulnerability, codenamed CVE-2025-61932 and rated CVSS v4: 9.3, affects locally installed versions of Lanscope Endpoint Manager , specifically the Client program and the Detection Agent, and could allow attackers to execute arbitrary code on vulnerable systems.

“Motex LANSCOPE Endpoint Manager contains improper verification of the source of a communication channel, allowing an attacker to execute arbitrary code by sending specially crafted packets,” CISA said. The vulnerability affects versions 9.4.7.1 and earlier. It has been addressed in later versions.

See also: TP-Link fixes vulnerabilities affecting Omada Gateways

Vulnerability in Lanscope Endpoint Manager allows cyberattacks

It is currently unknown how the vulnerability is being exploited in real-world attacks, who is behind them, or the extent of these efforts. However, a notice issued by the Japan Vulnerability Notes (JVN) earlier this week said that Motex has confirmed that an anonymous customer “received a malicious package suspected of targeting this vulnerability.”

In light of active exploitation efforts, it is recommended that Federal Citizens Executive Branch (FCEB) agencies patch CVE-2025-61932 by November 12, 2025, to protect their networks. This vulnerability highlights the importance of regularly updating security systems and applying the latest patches to prevent potential attacks.

See also: Critical flaw in more than 73,000 WatchGuard Firebox devices

Vulnerability in Lanscope Endpoint Manager allows cyberattacks

Organizations should closely monitor security announcements and ensure their infrastructure is protected from known vulnerabilities. Working with cybersecurity experts can help identify and address such threats before they are exploited by malicious actors. Additionally, educating staff on security best practices and awareness of the latest threats is critical to strengthening organizations’ overall security.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS