CVE-2025-32433
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- April 08, 2025
- Published Date
- April 16, 2025
- Last Updated
- April 25, 2025
- Vendor
- erlang
- Product
- otp
- Description
- Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
- Tags
- Score
- 70.46% (Percentile: 98.58%) as of 2025-06-13
- Exploitation
- poc
- Automatable
- Yes
- Technical Impact
- total
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
SSVC Information
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2025-06-11 08:45:31 UTC |
Recent Mentions
CISA Adds Erlang SSH and Roundcube Flaws to Known Exploited Vulnerabilities Catalog
Source: TheHackerNews • Published: 2025-06-10 05:37:00 UTC
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Source: All CISA Advisories • Published: 2025-06-09 12:00:00 UTC
Schneider Electric Galaxy VS, Galaxy VL, Galaxy VXL
Source: All CISA Advisories • Published: 2025-05-20 12:00:00 UTC
Multiple Cisco Products Unauthenticated Remote Code Execution in Erlang/OTP SSH Server: April 2025
Source: Cisco Security Advisory • Published: 2025-04-26 03:47:50 UTC
Reducing Remediation Time Remains a Challenge: How Tenable Vulnerability Watch Can Help
Source: Tenable Blog • Published: 2025-04-25 19:58:48 UTC
CVE-2025-32433
Source: Horizon3.ai Attack Research • Published: 2025-04-21 11:20:37 UTC
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/ssh/ssh_erlangotp_rce.rb | 2025-06-09 13:48:35 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
vigilante-1337/CVE-2025-32433
Type: github • Created: 2025-05-03 13:32:34 UTC • Stars: 0
bilalz5-github/Erlang-OTP-SSH-CVE-2025-32433
Type: github • Created: 2025-05-02 02:06:58 UTC • Stars: 0
C9b3rD3vi1/Erlang-OTP-SSH-CVE-2025-32433
Type: github • Created: 2025-04-29 21:15:30 UTC • Stars: 0
ODST-Forge/CVE-2025-32433_PoC
Type: github • Created: 2025-04-29 21:06:37 UTC • Stars: 0
abrewer251/CVE-2025-32433_Erlang-OTP_PoC
Type: github • Created: 2025-04-29 19:02:15 UTC • Stars: 0
abrewer251/CVE-2025-32433_Erlang-OTP
Type: github • Created: 2025-04-29 19:02:15 UTC • Stars: 0
Know56/CVE-2025-32433
Type: github • Created: 2025-04-28 20:04:49 UTC • Stars: 0
MrDreamReal/CVE-2025-32433
Type: github • Created: 2025-04-27 02:18:55 UTC • Stars: 0
becrevex/CVE-2025-32433
Type: github • Created: 2025-04-25 15:57:40 UTC • Stars: 1
0x7556/CVE-2025-32433
Type: github • Created: 2025-04-25 15:31:21 UTC • Stars: 1
rizky412/CVE-2025-32433
Type: github • Created: 2025-04-24 21:14:12 UTC • Stars: 0
ps-interactive/lab_CVE-2025-32433
Type: github • Created: 2025-04-24 13:22:06 UTC • Stars: 0
tobiasGuta/Erlang-OTP-CVE-2025-32433
Type: github • Created: 2025-04-23 20:12:50 UTC • Stars: 0
meloppeitreet/CVE-2025-32433-Remote-Shell
Type: github • Created: 2025-04-19 18:32:34 UTC • Stars: 0
omer-efe-curkus/CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC
Type: github • Created: 2025-04-18 21:11:44 UTC • Stars: 8
teamtopkarl/CVE-2025-32433
Type: github • Created: 2025-04-18 15:06:12 UTC • Stars: 1
LemieOne/CVE-2025-32433
Type: github • Created: 2025-04-18 10:53:19 UTC • Stars: 3
darses/CVE-2025-32433
Type: github • Created: 2025-04-18 10:30:52 UTC • Stars: 0
ekomsSavior/POC_CVE-2025-32433
Type: github • Created: 2025-04-18 02:32:41 UTC • Stars: 1
ProDefense/CVE-2025-32433
Type: github • Created: 2025-04-18 00:35:11 UTC • Stars: 85
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Proof of Concept Exploit Available
-
Detected by Metasploit
-
Added to KEVIntel