Lanscope Endpoint Manager vulnerability exploited in zero-day attacks (CVE-2025-61932)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-61932 | Unauthenticated RCE via spoofed packets in Motex LANSCOPE Endpoint Manager agents Motex LANSCOPE Endpoint Manager (On-Premises) — specifically its client program (MR) and detection agent (DA) components — fails to properly verify the source of incoming communications (CWE-940). An attacker who can reach a machine running the vulnerable agent over the network can send specially crafted packets and execute arbitrary code, with no privileges or user interaction required (CVSS 4.0: 9.3, critical, with high impact on confidentiality, integrity, and availability of the compromised endpoint). Organizations running the on-premises product, typically as agent software deployed across their managed endpoints, are affected. The flaw has been exploited as a zero-day in ongoing attacks, reportedly by the China-linked Tick group, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-22. No public proof-of-concept is known, but confirmed in-the-wild exploitation means patching should be treated as urgent. Do: Upgrade to the patched versions specified in Motex's security advisory (and the JPCERT coordination notice) as soon as possible; CISA KEV inclusion means U.S. federal agencies must patch or apply vendor mitigations per BOD 22-01. Until patched, restrict network access to the ports used for MR/DA agent communications and limit which network segments can send packets to agent hosts, since the flaw requires only network reachability. Given confirmed zero-day use by the China-linked Tick group, also hunt for signs of post-compromise lateral movement on endpoints running the agents. | 9.3 | 3% | KEV |
| masslikely 1M+ agent-installed endpoints across thousands of organizations, concentrated in Japan (exact install counts not published) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 9.3.3.9 | .6.3, 9.4.5.4, 9.4.4.6, 9.4.3.8, 9.4.2.6, 9.4.1.5, 9.4.0.5, 9.3.3.9, and 9.3.2.7. Organizations have been urged to update all c |
| ipv4 | 9.4.0.5 | .7.3, 9.4.6.3, 9.4.5.4, 9.4.4.6, 9.4.3.8, 9.4.2.6, 9.4.1.5, 9.4.0.5, 9.3.3.9, and 9.3.2.7. Organizations have been urged to upd |
| ipv4 | 9.4.1.5 | sions 9.4.7.3, 9.4.6.3, 9.4.5.4, 9.4.4.6, 9.4.3.8, 9.4.2.6, 9.4.1.5, 9.4.0.5, 9.3.3.9, and 9.3.2.7. Organizations have been urg |
| ipv4 | 9.4.2.6 | ed in versions 9.4.7.3, 9.4.6.3, 9.4.5.4, 9.4.4.6, 9.4.3.8, 9.4.2.6, 9.4.1.5, 9.4.0.5, 9.3.3.9, and 9.3.2.7. Organizations have |
| ipv4 | 9.4.3.8 | been fixed in versions 9.4.7.3, 9.4.6.3, 9.4.5.4, 9.4.4.6, 9.4.3.8, 9.4.2.6, 9.4.1.5, 9.4.0.5, 9.3.3.9, and 9.3.2.7. Organizat |
| ipv4 | 9.4.4.6 | 61932 has been fixed in versions 9.4.7.3, 9.4.6.3, 9.4.5.4, 9.4.4.6, 9.4.3.8, 9.4.2.6, 9.4.1.5, 9.4.0.5, 9.3.3.9, and 9.3.2.7. |
| ipv4 | 9.4.5.4 | CVE-2025-61932 has been fixed in versions 9.4.7.3, 9.4.6.3, 9.4.5.4, 9.4.4.6, 9.4.3.8, 9.4.2.6, 9.4.1.5, 9.4.0.5, 9.3.3.9, and |
| ipv4 | 9.4.6.3 | systems. CVE-2025-61932 has been fixed in versions 9.4.7.3, 9.4.6.3, 9.4.5.4, 9.4.4.6, 9.4.3.8, 9.4.2.6, 9.4.1.5, 9.4.0.5, 9.3. |
| ipv4 | 9.4.7.3 | lnerable systems. CVE-2025-61932 has been fixed in versions 9.4.7.3, 9.4.6.3, 9.4.5.4, 9.4.4.6, 9.4.3.8, 9.4.2.6, 9.4.1.5, 9.4. |
Full article444 words · extracted from helpnetsecurity.com · click to collapse
CVE-2025-61932, an “improper verification of source of a communication channel” vulnerability affecting Lanscope Endpoint Manager, has been exploited as a zero-day since April 2025, the Japan Computer Emergency Response Team Coordination Center (JPCERT/CC) warned on Wednesday.
According to information received from the solution’s vendor, Motex Inc., a Japanese cybersecurity/IT tools company, Japan-based customers have been targeted with exploit attempts.
Based on vendor claims, the Lanscope Endpoint Manager has significant adoption in Japan, particularly among financial institutions, but its global presence appears to be far more limited.
Nevertheless, the US Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring US federal civilian agencies to remediate it within three weeks.
About CVE-2025-61932
Lanscope Endpoint Manager is an endpoint management and security solution that has a SaaS/cloud version (unaffected by this vulnerability) and an on-premises version.
The law can be exploited by sending specially crafted packets to TCP port 443 on systems running affected software: the client program (MR) and detection agent (DA) components of Lanscope Endpoint Manager On-Premise v9.4.7.1 and earlier.
Such packets may allow attackers to execute arbitrary code on vulnerable systems.
CVE-2025-61932 has been fixed in versions 9.4.7.3, 9.4.6.3, 9.4.5.4, 9.4.4.6, 9.4.3.8, 9.4.2.6, 9.4.1.5, 9.4.0.5, 9.3.3.9, and 9.3.2.7.
Organizations have been urged to update all client PCs. The management server software is not affected and doesn’t need to be upgraded, according to Motex.
“If managed endpoints with the client program (MR) or detection agent (DA) installed are deployed in environments that are accessible from external networks, the likelihood of attack attempts exploiting this vulnerability is expected to increase,” JPCERT/CC stated.
Windows servers exposed to the Internet, devices assigned a public/global IP address, and Lanscope Endpoint Manager servers with MR or DA installed are at elevated risk of compromise, the agency added.
JPCERT/CC has published a list of IP addresses used to send malicious packets as well as command-and-control IP addresses contacted by the attacker-installed backdoor.
UPDATE (October 30, 2025, 07:05 p.m. ET):
Sophos has revealed details about the attacks in which CVE-2025-61932 had been leveraged:
- The attacks have been attributed to Chinese state-sponsored APT Bronze Butler, which “has been active since 2010 and previously exploited a zero-day vulnerability in Japanese asset management product SKYSEA Client View in 2016”
- The attackers used the Gokcpdoor malware to establish a backdoor on compromised hosts and achieve remote access
- They used the Havoc C2 framework and OAED Loader malware (previously linked to the group), and a number of known and legitimate tools for lateral movement and data exfiltration.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/10/23/cve-2025-61932-lanscope-endpoint-manager-exploited/