CVE-2025-32433
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- April 08, 2025
- Published Date
- April 16, 2025
- Last Updated
- February 26, 2026
- Vendor
- erlang
- Product
- otp
- Description
- Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
- Tags
- Score
- 59.72% (Percentile: 98.29%) as of 2026-05-31
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
SSVC Information
References
Known Exploited Vulnerability Information
| Source | Added Date |
|---|---|
| CVE | 2026-06-01 10:32:20 UTC |
Recent Mentions
Reducing Remediation Time Remains a Challenge: How Tenable Vulnerability Watch Can Help
Source: Tenable Blog • Published: 2025-04-25 19:58:48 UTC
Multiple Cisco Products Unauthenticated Remote Code Execution in Erlang/OTP SSH Server: April 2025
Source: Cisco Security Advisory • Published: 2025-04-25 03:20:26 UTC
CVE-2025-32433
Source: Horizon3.ai Attack Research • Published: 2025-04-21 11:20:37 UTC
Scanner Integrations
| Scanner | URL | Date Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/ssh/ssh_erlangotp_rce.rb | 2025-06-09 13:36:56 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
MrDreamReal/CVE-2025-32433
Type: github • Created: 2025-04-27 02:18:55 UTC • Stars: 0
becrevex/CVE-2025-32433
Type: github • Created: 2025-04-25 15:57:40 UTC • Stars: 1
0x7556/CVE-2025-32433
Type: github • Created: 2025-04-25 15:31:21 UTC • Stars: 1
rizky412/CVE-2025-32433
Type: github • Created: 2025-04-24 21:14:12 UTC • Stars: 0
ps-interactive/lab_CVE-2025-32433
Type: github • Created: 2025-04-24 13:22:06 UTC • Stars: 0
tobiasGuta/Erlang-OTP-CVE-2025-32433
Type: github • Created: 2025-04-23 20:12:50 UTC • Stars: 0
meloppeitreet/CVE-2025-32433-Remote-Shell
Type: github • Created: 2025-04-19 18:32:34 UTC • Stars: 0
omer-efe-curkus/CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC
Type: github • Created: 2025-04-18 21:11:44 UTC • Stars: 8
teamtopkarl/CVE-2025-32433
Type: github • Created: 2025-04-18 15:06:12 UTC • Stars: 1
LemieOne/CVE-2025-32433
Type: github • Created: 2025-04-18 10:53:19 UTC • Stars: 3
darses/CVE-2025-32433
Type: github • Created: 2025-04-18 10:30:52 UTC • Stars: 0
Epivalent/CVE-2025-32433-detection
Type: github • Created: 2025-04-18 09:56:23 UTC • Stars: 0
ekomsSavior/POC_CVE-2025-32433
Type: github • Created: 2025-04-18 02:32:41 UTC • Stars: 1
ProDefense/CVE-2025-32433
Type: github • Created: 2025-04-18 00:35:11 UTC • Stars: 85
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Proof of Concept Exploit Available
-
Detected by Metasploit
-
Added to KEVIntel