9.8 CVE-2025-61932

CISA Kev Catalog RCI
 

Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.
https://nvd.nist.gov/vuln/detail/CVE-2025-61932

Categories

CWE-940 : Improper Verification of Source of a Communication Channel
When an attacker can successfully establish a communication channel from an untrusted origin, the attacker may be able to gain privileges and access unexpected functionality.

References

134c704f-9b21-4f2e-91b3-4a467353bcc0

vultures@jpcert.or.jp


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:motex:lanscope_endpoint_manager:*:*:*:*:on-premise:*:*:* < 9.3.2.7
cpe:2.3:a:motex:lanscope_endpoint_manager:*:*:*:*:on-premise:*:*:* >= 9.3.3.0 < 9.3.3.9
cpe:2.3:a:motex:lanscope_endpoint_manager:*:*:*:*:on-premise:*:*:* >= 9.4.0.0 < 9.4.0.5
cpe:2.3:a:motex:lanscope_endpoint_manager:*:*:*:*:on-premise:*:*:* >= 9.4.1.0 < 9.4.1.5
cpe:2.3:a:motex:lanscope_endpoint_manager:*:*:*:*:on-premise:*:*:* >= 9.4.2.0 < 9.4.2.6
cpe:2.3:a:motex:lanscope_endpoint_manager:*:*:*:*:on-premise:*:*:* >= 9.4.3.0 < 9.4.3.8
cpe:2.3:a:motex:lanscope_endpoint_manager:*:*:*:*:on-premise:*:*:* >= 9.4.4.0 < 9.4.4.6
cpe:2.3:a:motex:lanscope_endpoint_manager:*:*:*:*:on-premise:*:*:* >= 9.4.5.0 < 9.4.5.4
cpe:2.3:a:motex:lanscope_endpoint_manager:*:*:*:*:on-premise:*:*:* >= 9.4.6.0 < 9.4.6.3
cpe:2.3:a:motex:lanscope_endpoint_manager:*:*:*:*:on-premise:*:*:* >= 9.4.7.0 <= 9.4.7.1


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
500 WebView Injection
595 Connection Reset
594 Traffic Injection
596 TCP RST Injection