Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
Published: 2025-04-18
Proof-of-concept code has been released after researchers disclosed a maximum severity remote code execution vulnerability in Erlang/OTP SSH. Successful exploitation could allow for complete takeover of affected devices.
https://security.netapp.com/advisory/ntap-20250425-0001/
https://lists.debian.org/debian-lts-announce/2025/04/msg00028.html
https://securelist.com/vulnerabilities-and-exploits-in-q2-2026/121091/
https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/
https://www.infosecurity-magazine.com/news/erlangotp-ssh-flaw-sees/
https://www.darkreading.com/ics-ot-security/patch-now-attackers-target-ot-networks-critical-rce-flaw
https://unit42.paloaltonetworks.com/erlang-otp-cve-2025-32433/
https://thehackernews.com/2025/08/researchers-spot-surge-in-erlangotp-ssh.html
https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-06
https://securelist.com/vulnerabilities-and-exploits-in-q2-2025/117333/
https://www.cisa.gov/news-events/ics-advisories/icsa-25-140-07
https://www.securityweek.com/cisco-patches-35-vulnerabilities-across-several-products/
https://thehackernews.com/2025/04/critical-erlangotp-ssh-vulnerability.html
https://github.com/Liam-Worsley/CVE-2025-32433-PoC-Analysis
https://github.com/diedromeo/CVE-Labs-2025-2026
https://github.com/dampedcoast/Exploiting-a-vulnerability-using-reverse-shell
https://github.com/chuzouX/CVE-2025-32433-Exploit-edited
https://github.com/staatik/fragchain-core
https://github.com/DavidEspin141/TFG-Pentesting-IA
https://github.com/EvanThomasLuke/HACK-AGI-CONTAINERS
https://github.com/agustfricke/erlang-ssh-rce-CVE-2025-32433
https://github.com/mystichackers/CVE-2025
https://github.com/carlosalbertotuma/CVE-2025-32433
https://github.com/giriaryan694-a11y/cve-2025-32433_rce_exploit
https://github.com/Lucas-Cyber-Security/CVE_Projects
https://github.com/soltanali0/CVE-2025-32433-Eploit
https://github.com/pwnk1t/cve-collection
https://github.com/l1nuxkid/CVE-2025-32433-exploit
https://github.com/V0idA2tronaut/CVEs
https://github.com/mirmeweu/cve-2025-32433
https://github.com/te0rwx/CVE-2025-32433-Detection
https://github.com/AnonUsenix/LLM_Agent_Cybersecurity_Forensic
https://github.com/hackermexico/chacal
https://github.com/gnaohuv/CVE_research_report
https://github.com/B1ack4sh/Blackash-CVE-2025-32433
https://github.com/Vip3r-MC/VulnVault
https://github.com/vigilante-1337/CVE-2025-32433
https://github.com/colinlyons29/redteam-walkthroughs
https://github.com/C9b3rD3vi1/Erlang-OTP-SSH-CVE-2025-32433
https://github.com/ODST-Forge/CVE-2025-32433_PoC
https://github.com/abrewer251/CVE-2025-32433_Erlang-OTP_PoC
https://github.com/abrewer251/CVE-2025-32433_Erlang-OTP
https://github.com/Know56/CVE-2025-32433
https://github.com/MrDreamReal/CVE-2025-32433
https://github.com/0x7556/CVE-2025-32433
https://github.com/rizky412/CVE-2025-32433
https://github.com/TeneBrae93/CVE-2025-3243
https://github.com/ps-interactive/lab_CVE-2025-32433
https://github.com/tobiasGuta/Erlang-OTP-CVE-2025-32433
https://github.com/SDX442/CVE-2025-32433
https://github.com/omer-efe-curkus/CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC
https://github.com/exa-offsec/ssh_erlangotp_rce
https://github.com/m0usem0use/erl_mouse
https://github.com/teamtopkarl/CVE-2025-32433
https://github.com/LemieOne/CVE-2025-32433
https://github.com/heqnx/cve-poc-mon
https://github.com/accuknox/CVE-PoC-Collection
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32433
https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2
https://github.com/erlang/otp/commit/b1924d37fd83c070055beb115d5d6a6a9490b891
https://github.com/erlang/otp/commit/6eef04130afc8b0ccb63c9a0d8650209cf54892f
https://github.com/erlang/otp/commit/0fcd9c56524b28615e8ece65fc0c3f66ef6e4c12
http://www.openwall.com/lists/oss-security/2025/04/19/1
http://www.openwall.com/lists/oss-security/2025/04/18/6
http://www.openwall.com/lists/oss-security/2025/04/18/2
Published: 2025-04-16
Updated: 2025-11-04
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 10
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity: Critical
EPSS: 0.98754
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest