Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacker to tamper with arbitrary files and execute arbitrary code on the affected system.
The vulnerability results from improper file path validation in the Sub-Manager Server component (CWE-22 — path traversal). An attacker can send a crafted network request containing directory traversal sequences (e.g., '../'), which allows escaping the allowed working directory and gaining access to arbitrary files on the operating system. By modifying these files, arbitrary code execution (RCE) on the server becomes possible.
An unauthenticated attacker can modify any files on the server and execute arbitrary code on it, which may lead to complete system compromise.
Sub-Manager Server should be updated to a version newer than 9.4.7.3, applying patches available from the vendor according to information published by Motex at https://www.motex.co.jp/news/notice/2026/release260225/ and in the JVN#79096585 bulletin.
Motex Lanscope Endpoint Manager (On-Premises) — Sub-Manager Server in version 9.4.7.3 and earlier
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMotex Lanscope Endpoint Manager
APPMotex< 9.4.8.0