CVE-2025-61932
Motex · Published October 20, 2025
9.8
CVSS v3.1
CRITICALCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.
Affected Products
- Lanscope Endpoint Manager < 9.3.2.7
- Lanscope Endpoint Manager < 9.3.3.9
- Lanscope Endpoint Manager < 9.4.0.5
- Lanscope Endpoint Manager < 9.4.1.5
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H