# LANSCOPE Endpoint Manager RCE flaw exploited

Published: 2025-10-19 · Severity: critical
Canonical: https://vorant.io/reports/1b4f9128-5cb9-56a5-aa46-5643aac3cc24/lanscope-endpoint-manager-rce-flaw-exploited

> A critical CVE-2025-61932 flaw in MOTEX LANSCOPE Endpoint Manager (on-premise) lets attackers achieve remote code execution via crafted packets, with real-world exploitation confirmed.

IPA/JVN issued an advisory for CVE-2025-61932, a critical vulnerability (CVSS v3 9.8) in MOTEX's LANSCOPE Endpoint Manager on-premise edition, affecting the client program (MR) and detection agent (DA) in versions 9.4.7.1 and earlier. The flaw stems from insufficient source validation of the product's communication channel, allowing an attacker who sends specially crafted packets to execute arbitrary code on the affected system.

The vendor has confirmed that malicious packets originating from external sources have already been observed hitting customer environments, indicating active exploitation attempts in the wild rather than a purely theoretical risk. The cloud version of LANSCOPE Endpoint Manager is not affected. Organizations running the on-premise version are urged to update to the patched release or apply the vendor's workaround immediately, given the endpoint management tool's typically privileged position within enterprise networks.

## Mentioned in this report

- Vulnerabilities: CVE-2025-61932 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/20251020-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1b4f9128-5cb9-56a5-aa46-5643aac3cc24/lanscope-endpoint-manager-rce-flaw-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
