Safeguard
Vulnerability Analysis

A VPN Gateway and an Endpoint Manager, Both Compromised by Trusting Remote Input

Array Networks' ArrayOS AG command injection and Motex LANSCOPE's communication-channel verification flaw are unrelated products that share the same structural weakness: infrastructure built to be trusted rather than to verify.

Safeguard Research Team
5 min read

Two unrelated vendors, Array Networks and Motex, each had a single vulnerability confirmed exploited and added to CISA's KEV catalogue within roughly six weeks of each other in late 2025 — an OS command injection bug in a VPN gateway and a communication-channel verification flaw in an endpoint management client — and together they illustrate why the infrastructure meant to secure or manage a network is so often where attackers actually get in.

CVECVSSVendor / ProductAdded to KEV
CVE-2025-666447.2Array Networks ArrayOS AG8 Dec 2025
CVE-2025-619329.3Motex LANSCOPE Endpoint Manager22 Oct 2025

Why an SSL-VPN and an endpoint manager belong in the same conversation

Array Networks' ArrayOS AG is SSL-VPN gateway software, and Motex's LANSCOPE Endpoint Manager is an on-premises client/agent system for managing and monitoring corporate endpoints — different products from different vendors solving different problems, but occupying the same structural position in an organization's security architecture: both are trusted, privileged infrastructure that every other system on the network is configured to defer to. A VPN gateway is, by design, the boundary every remote connection passes through before reaching internal resources. An endpoint manager is, by design, granted the ability to push configuration and code to every machine it monitors. When either category of software has an exploitable flaw, the resulting compromise doesn't stay contained to "one server" — it inherits the reach the tool itself was built to have.

CVE-2025-66644 is OS command injection in ArrayOS AG, and NVD's description is unusually direct about its status: the product "allows command injection, as exploited in the wild in August through December 2025" — meaning this bug was under active attack for roughly four months before formal KEV inclusion caught up to what was already happening. A BleepingComputer report referenced in this CVE's disclosure describes attackers using the flaw specifically to plant webshells, the standard playbook for turning a command injection bug in internet-facing gateway software into durable, remotely accessible persistence.

CVE-2025-61932 is even more severe at 9.3 under CVSS 4.0 scoring, and its root cause — improper verification of the source of a communication channel (CWE-940) — is a different but related failure mode: LANSCOPE's client program and detection agent don't properly verify where incoming requests actually originate, which means an attacker capable of reaching that communication channel can send specially crafted packets and achieve arbitrary code execution without needing to compromise a legitimate management server first. A Japanese vendor advisory and a JVN (Japan Vulnerability Notes) entry both document this finding, consistent with LANSCOPE's substantial install base in Japan and the broader Asia-Pacific region.

The shared root cause: infrastructure built to be trusted, not built to verify

What connects a VPN command injection bug and an endpoint manager's communication-verification failure is a pattern seen across this entire class of network- and endpoint-management infrastructure: software whose core function requires accepting and acting on remote input — VPN connection requests, endpoint check-in packets, configuration commands — often under-invests in verifying that input's legitimacy relative to how much power that input is allowed to exercise once accepted. ArrayOS AG needed to accept and process connection parameters from remote clients; somewhere in that processing, insufficient input sanitization allowed OS-level command execution. LANSCOPE needed to accept check-in and control communication from its own distributed agents; somewhere in that channel, the software failed to adequately confirm the traffic it was accepting truly originated from a legitimate agent rather than an attacker impersonating one.

What to check this week

Patch ArrayOS AG to 9.4.5.9 or later immediately given documented exploitation dating back to August 2025 — four months of active attack before KEV listing means any unpatched instance should be treated as potentially already compromised, not merely at risk.

Inspect internet-facing ArrayOS AG gateways for webshells specifically, per the documented attacker technique, rather than assuming a clean patch alone resolves prior compromise if the system was exposed during the August–December 2025 exploitation window.

Apply Motex's patch referenced in their October 2025 advisory across every LANSCOPE client and detection agent deployment, prioritizing this over the ArrayOS finding given its higher 9.3 severity score and lack of required user interaction or authentication.

Segment and restrict the network paths LANSCOPE agents use to communicate with their management server, since the underlying flaw is a verification failure on that communication channel — reducing which network segments can reach it narrows the attack surface even ahead of patching.

A closing note on trusting the tools that secure and manage everything else

VPN gateways and endpoint management platforms are deployed specifically because an organization needs a single trusted point of control over remote access or fleet-wide configuration — and that same centralization is precisely what makes a flaw in either category disproportionately consequential compared to an equivalent bug in a standalone application serving no other system.

How Safeguard helps

Safeguard's continuous inventory treats VPN gateways, SSL-VPN appliances, and endpoint management platforms as elevated-priority infrastructure specifically because of the trust and reach both categories carry, surfacing findings like these two — one already under four months of active exploitation before formal confirmation — well ahead of a routine patch cycle catching up.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.