# CVE-2025-61932

## Summary

- **CVE ID:** CVE-2025-61932
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-940
- **Published:** Oct 20, 2025
- **Last Modified:** Feb 26, 2026

## Description

Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.

## Affected Products

- MOTEX Inc. — Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) (Ver.9.4.7.1 and earlier)

## References

- [CNA](https://www.motex.co.jp/news/notice/2025/release251020/)
- [CNA](https://jvn.jp/en/jp/JVN86318557/)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61932)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 2.63%
- **EPSS Percentile:** 84.6

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Oct 22, 2025
- **Due Date:** Nov 12, 2025

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._