LANSCOPE Endpoint Manager Vulnerability Let Attackers Execute Remote Code
## LANSCOPE Endpoint Manager Vulnerability
LANSCOPE Endpoint Manager Vulnerability
Motex has identified a critical remote code execution vulnerability in its LANSCOPE Endpoint Manager On-Premise Edition, designated as CVE-2025-61932. This flaw has been assigned a CVSS 3.0 score of 9.8, indicating an emergency-level threat.
The vulnerability enables attackers to execute arbitrary code on compromised systems, potentially leading to the full compromise of endpoint devices. It affects the product's Client Program (MR) and Detection Agent (DA), which are key components in managing and monitoring endpoint security.
Versions up to 9.4.7.1 are vulnerable. The cloud-based edition is not affected, safeguarding SaaS users from immediate risks. However, organizations using the on-premise version, often preferred for enhanced control over IT environments, should promptly address this issue.
There is evidence of active exploitation, with confirmed cases of malicious packets being sent to customer environments from external sources. Attackers are targeting client-side programs, exploiting weaknesses that bypass standard network defenses. Although security researchers suspect improper input validation as a potential cause, full technical analysis remains pending.
Motex has identified a critical remote code execution vulnerability in its LANSCOPE Endpoint Manager On-Premise Edition, designated as CVE-2025-61932.
This vulnerability highlights the inherent risks in endpoint management tools, which often operate with elevated privileges. Successful exploitation could result in malware deployment, data theft, or further network infiltration. Due to its high CVSS score, driven by factors such as network accessibility and low complexity, organizations are advised to prioritize remediation.
Motex has released a fix accessible through their customer support portal, LANSCOPE PORTAL. The update is specific to client PCs, with no changes required for the central manager. Deployment follows standard procedures, facilitating straightforward implementation by IT teams.
As of August 2025, no widespread breaches have been publicly attributed to this CVE, but the confirmed malicious activities underscore the potential for rapid escalation. Cybersecurity experts recommend immediate patching, particularly in hybrid work environments where endpoints connect remotely.
Based on reporting by Cyber Security News.
