CVE-2025-32433

critical

Description

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

From the Tenable Blog

CVE-2025-32433: Erlang/OTP SSH Unauthenticated Remote Code Execution Vulnerability
CVE-2025-32433: Erlang/OTP SSH Unauthenticated Remote Code Execution Vulnerability

Published: 2025-04-18

Proof-of-concept code has been released after researchers disclosed a maximum severity remote code execution vulnerability in Erlang/OTP SSH. Successful exploitation could allow for complete takeover of affected devices.

References

https://github.com/Liam-Worsley/CVE-2025-32433-PoC-Analysis

https://github.com/diedromeo/CVE-Labs-2025-2026

https://github.com/dampedcoast/Exploiting-a-vulnerability-using-reverse-shell

https://github.com/chuzouX/CVE-2025-32433-Exploit-edited

https://github.com/staatik/fragchain-core

https://github.com/DavidEspin141/TFG-Pentesting-IA

https://github.com/EvanThomasLuke/HACK-AGI-CONTAINERS

https://github.com/agustfricke/erlang-ssh-rce-CVE-2025-32433

https://github.com/mystichackers/CVE-2025

https://github.com/carlosalbertotuma/CVE-2025-32433

https://github.com/giriaryan694-a11y/cve-2025-32433_rce_exploit

https://github.com/Lucas-Cyber-Security/CVE_Projects

https://github.com/soltanali0/CVE-2025-32433-Eploit

https://github.com/pwnk1t/cve-collection

https://github.com/l1nuxkid/CVE-2025-32433-exploit

https://github.com/V0idA2tronaut/CVEs

https://github.com/mirmeweu/cve-2025-32433

https://github.com/te0rwx/CVE-2025-32433-Detection

https://github.com/AnonUsenix/LLM_Agent_Cybersecurity_Forensic

https://github.com/hackermexico/chacal

https://github.com/gnaohuv/CVE_research_report

https://github.com/B1ack4sh/Blackash-CVE-2025-32433

https://github.com/Vip3r-MC/VulnVault

https://github.com/vigilante-1337/CVE-2025-32433

https://github.com/colinlyons29/redteam-walkthroughs

https://github.com/C9b3rD3vi1/Erlang-OTP-SSH-CVE-2025-32433

https://github.com/ODST-Forge/CVE-2025-32433_PoC

https://github.com/abrewer251/CVE-2025-32433_Erlang-OTP_PoC

https://github.com/abrewer251/CVE-2025-32433_Erlang-OTP

https://github.com/Know56/CVE-2025-32433

https://github.com/MrDreamReal/CVE-2025-32433

https://github.com/0x7556/CVE-2025-32433

https://github.com/rizky412/CVE-2025-32433

https://github.com/TeneBrae93/CVE-2025-3243

https://github.com/ps-interactive/lab_CVE-2025-32433

https://github.com/tobiasGuta/Erlang-OTP-CVE-2025-32433

https://github.com/SDX442/CVE-2025-32433

https://github.com/omer-efe-curkus/CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC

https://github.com/exa-offsec/ssh_erlangotp_rce

https://github.com/m0usem0use/erl_mouse

https://github.com/teamtopkarl/CVE-2025-32433

https://github.com/LemieOne/CVE-2025-32433

https://github.com/heqnx/cve-poc-mon

https://github.com/accuknox/CVE-PoC-Collection

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32433

https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2

https://github.com/erlang/otp/commit/b1924d37fd83c070055beb115d5d6a6a9490b891

https://github.com/erlang/otp/commit/6eef04130afc8b0ccb63c9a0d8650209cf54892f

https://github.com/erlang/otp/commit/0fcd9c56524b28615e8ece65fc0c3f66ef6e4c12

http://www.openwall.com/lists/oss-security/2025/04/19/1

http://www.openwall.com/lists/oss-security/2025/04/18/6

http://www.openwall.com/lists/oss-security/2025/04/18/2

http://www.openwall.com/lists/oss-security/2025/04/18/1

http://www.openwall.com/lists/oss-security/2025/04/16/2

Details

Source: Mitre, NVD

Published: 2025-04-16

Updated: 2025-11-04

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 10

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.98754

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest