ZeroHour

CVE-2025-61932

KEVmass1

Unauthenticated RCE via spoofed packets in Motex LANSCOPE Endpoint Manager agents

CISA: Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability

CVSS 4.0
9.3 critical
EPSS
3%p85
Published
()
KEV added
AI analysis

Motex LANSCOPE Endpoint Manager (On-Premises) — specifically its client program (MR) and detection agent (DA) components — fails to properly verify the source of incoming communications (CWE-940). An attacker who can reach a machine running the vulnerable agent over the network can send specially crafted packets and execute arbitrary code, with no privileges or user interaction required (CVSS 4.0: 9.3, critical, with high impact on confidentiality, integrity, and availability of the compromised endpoint). Organizations running the on-premises product, typically as agent software deployed across their managed endpoints, are affected. The flaw has been exploited as a zero-day in ongoing attacks, reportedly by the China-linked Tick group, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-22. No public proof-of-concept is known, but confirmed in-the-wild exploitation means patching should be treated as urgent.

What to do: Upgrade to the patched versions specified in Motex's security advisory (and the JPCERT coordination notice) as soon as possible; CISA KEV inclusion means U.S. federal agencies must patch or apply vendor mitigations per BOD 22-01. Until patched, restrict network access to the ports used for MR/DA agent communications and limit which network segments can send packets to agent hosts, since the flaw requires only network reachability. Given confirmed zero-day use by the China-linked Tick group, also hunt for signs of post-compromise lateral movement on endpoints running the agents.

Affected
Motex LANSCOPE Endpoint Manager (On-Premises) — Client program (MR)
Motex LANSCOPE Endpoint Manager (On-Premises) — Detection agent (DA)
Estimated exposure
masslikely 1M+ agent-installed endpoints across thousands of organizations, concentrated in Japan (exact install counts not published) — LANSCOPE Endpoint Manager is one of the most widely deployed enterprise endpoint-management suites in Japan, and because the vulnerable MR/DA components are agent software installed on every managed endpoint, the on-premises install base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.

CISA Known Exploited Vulnerability
Affected
Motex LANSCOPE Endpoint Manager
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
motex
Products
lanscope endpoint manager
Weakness
CWE-940
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news