Lizardsystems develops a narrow product portfolio of remote-access and terminal-management tools, notably LanSpy and Terminal Services Manager, which serve specialized administrative use cases. The observed vulnerability pattern centers on memory-safety and authentication-control issues—out-of-bounds writes and missing authentication for critical functions—that reflect the direct-access and privileged-operation context of these products. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lizardsystems over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-25268HIGH LanSpy 2.0.1.159 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction pointer by supplying oversized input to the scan field. Attackers | Apr 22, 2026 | 8.4 | 27 | NO | NO |
CVE-2018-25265HIGH LanSpy 2.0.1.159 contains a local buffer overflow vulnerability in the scan section that allows local attackers to execute arbitrary code by exploiting structured exception handlin | Apr 22, 2026 | 8.4 | 27 | NO | NO |
CVE-2018-25259HIGH Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary code by triggering s | Apr 22, 2026 | 8.4 | 27 | NO | NO |
CVE-2019-25545MEDIUM Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the compute | Mar 21, 2026 | 6.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lizardsystems.
Media articles that mention a CVE ID that affects a product developed by Lizardsystems — matched by CVE ID, not by vendor name.