CRITICAL
CVE-2025-61932
CVSS
9.8
KEV
Description
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.
Summary dbcve.org
Lanscope Endpoint Manager On-Premises (Client program MR and Detection agent DA) contains an improper origin verification flaw that allows remote attackers to send specially crafted packets and execute arbitrary code without authentication.
Mitigation
Apply vendor-provided patches immediately; until available, restrict network access to the MR and DA services using firewall rules or network segmentation to only trusted IP addresses.
Weakness (CWE)
CWE-940
EPSS Score
2.63%
Probability of exploitation in next 30 days
84.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.