Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.
Software components — client program (MR) and detection agent (DA) — improperly verify the origin of incoming network requests (CWE-940: Improper Verification of Source of a Communication Channel). An attacker can send specially crafted packets that will be accepted as trusted, enabling arbitrary code execution on the target system without requiring authentication.
A remote attacker, without any privileges, can execute arbitrary code on a system running Lanscope Endpoint Manager, which may lead to full device takeover, data theft, or further network movement (lateral movement).
Security patches available from the vendor should be applied immediately according to the references (https://www.motex.co.jp/news/notice/2025/release251020/ and https://jvn.jp/en/jp/JVN86318557/). Due to active exploitation of the vulnerability, the update should be carried out as a priority and without delay.
Motex Lanscope Endpoint Manager (On-Premises) — components: Client program (MR) and Detection agent (DA); specific versions indicated in vendor references
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMotex Lanscope Endpoint Manager
APPMotex< 9.3.2.79.3.3.0 – 9.3.3.9 (excl.)9.4.0.0 – 9.4.0.5 (excl.)9.4.1.0 – 9.4.1.5 (excl.)9.4.2.0 – 9.4.2.6 (excl.)9.4.3.0 – 9.4.3.8 (excl.)9.4.4.0 – 9.4.4.6 (excl.)9.4.5.0 – 9.4.5.4 (excl.)9.4.6.0 – 9.4.6.3 (excl.)9.4.7.0 – 9.4.7.1
CISA KEV — detailsi
- Vendori
- Motex
- Producti
- LANSCOPE Endpoint Manager
- Added to KEVi
- October 22, 2025
- Remediation deadline (US Federal)i
- November 12, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packets.