U.S. CISA adds Motex LANSCOPE flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-61932 | Unauthenticated RCE via spoofed packets in Motex LANSCOPE Endpoint Manager agents Motex LANSCOPE Endpoint Manager (On-Premises) — specifically its client program (MR) and detection agent (DA) components — fails to properly verify the source of incoming communications (CWE-940). An attacker who can reach a machine running the vulnerable agent over the network can send specially crafted packets and execute arbitrary code, with no privileges or user interaction required (CVSS 4.0: 9.3, critical, with high impact on confidentiality, integrity, and availability of the compromised endpoint). Organizations running the on-premises product, typically as agent software deployed across their managed endpoints, are affected. The flaw has been exploited as a zero-day in ongoing attacks, reportedly by the China-linked Tick group, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-22. No public proof-of-concept is known, but confirmed in-the-wild exploitation means patching should be treated as urgent. Do: Upgrade to the patched versions specified in Motex's security advisory (and the JPCERT coordination notice) as soon as possible; CISA KEV inclusion means U.S. federal agencies must patch or apply vendor mitigations per BOD 22-01. Until patched, restrict network access to the ports used for MR/DA agent communications and limit which network segments can send packets to agent hosts, since the flaw requires only network reachability. Given confirmed zero-day use by the China-linked Tick group, also hunt for signs of post-compromise lateral movement on endpoints running the agents. | 9.3 | 3% | KEV |
| masslikely 1M+ agent-installed endpoints across thousands of organizations, concentrated in Japan (exact install counts not published) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 9.3.2.7 | 4.7.1 and earlier. The following versions address the flaw: 9.3.2.7 9.3.3.9 9.4.0.5 9.4.1.5 9.4.2.6 9.4.3.8 9.4.4.6 9.4.5.4 9.4 |
| ipv4 | 9.3.3.9 | d earlier. The following versions address the flaw: 9.3.2.7 9.3.3.9 9.4.0.5 9.4.1.5 9.4.2.6 9.4.3.8 9.4.4.6 9.4.5.4 9.4.6.3, an |
| ipv4 | 9.4.0.5 | r. The following versions address the flaw: 9.3.2.7 9.3.3.9 9.4.0.5 9.4.1.5 9.4.2.6 9.4.3.8 9.4.4.6 9.4.5.4 9.4.6.3, and 9.4.7. |
| ipv4 | 9.4.1.5 | ollowing versions address the flaw: 9.3.2.7 9.3.3.9 9.4.0.5 9.4.1.5 9.4.2.6 9.4.3.8 9.4.4.6 9.4.5.4 9.4.6.3, and 9.4.7.3 Accord |
| ipv4 | 9.4.2.6 | versions address the flaw: 9.3.2.7 9.3.3.9 9.4.0.5 9.4.1.5 9.4.2.6 9.4.3.8 9.4.4.6 9.4.5.4 9.4.6.3, and 9.4.7.3 According to B |
| ipv4 | 9.4.3.8 | s address the flaw: 9.3.2.7 9.3.3.9 9.4.0.5 9.4.1.5 9.4.2.6 9.4.3.8 9.4.4.6 9.4.5.4 9.4.6.3, and 9.4.7.3 According to Binding O |
| ipv4 | 9.4.4.6 | s the flaw: 9.3.2.7 9.3.3.9 9.4.0.5 9.4.1.5 9.4.2.6 9.4.3.8 9.4.4.6 9.4.5.4 9.4.6.3, and 9.4.7.3 According to Binding Operation |
| ipv4 | 9.4.5.4 | aw: 9.3.2.7 9.3.3.9 9.4.0.5 9.4.1.5 9.4.2.6 9.4.3.8 9.4.4.6 9.4.5.4 9.4.6.3, and 9.4.7.3 According to Binding Operational Direc |
| ipv4 | 9.4.6.3 | 2.7 9.3.3.9 9.4.0.5 9.4.1.5 9.4.2.6 9.4.3.8 9.4.4.6 9.4.5.4 9.4.6.3, and 9.4.7.3 According to Binding Operational Directive (BO |
| ipv4 | 9.4.7.1 | ts.” reads the advisory. The vulnerability impacts versions 9.4.7.1 and earlier. The following versions address the flaw: 9.3.2 |
| ipv4 | 9.4.7.3 | .4.0.5 9.4.1.5 9.4.2.6 9.4.3.8 9.4.4.6 9.4.5.4 9.4.6.3, and 9.4.7.3 According to Binding Operational Directive (BOD) 22-01: Red |
Full article238 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Motex LANSCOPE flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Motex LANSCOPE flaw, tracked as CVE-2025-61932 (CVSS v4 score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog.
The flaw is an improper verification of source of a communication channel vulnerability that allows an attacker to execute arbitrary code by sending specially crafted packets.
A flaw in the on-premises client and detection agent of Lanscope Endpoint Manager allows remote code execution via specially crafted packets due to improper request origin validation.
“Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packets.” reads the advisory.
The vulnerability impacts versions 9.4.7.1 and earlier. The following versions address the flaw:
- 9.3.2.7
- 9.3.3.9
- 9.4.0.5
- 9.4.1.5
- 9.4.2.6
- 9.4.3.8
- 9.4.4.6
- 9.4.5.4
- 9.4.6.3, and
- 9.4.7.3
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by November 12, 2025.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/183768/breaking-news/u-s-cisa-adds-motex-lanscope-flaw-to-its-known-exploited-vulnerabilities-catalog.html