CVE-2025-32433

Published Apr 16, 2025

Last updated 9 months ago

Exploit knownCVSS critical 10.0
Erlang
OTP
SSH
IoT
OT
Port (22)
HTTP

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-32433 is a vulnerability found in the Erlang/OTP SSH server. It stems from a flaw in the SSH protocol message handling, which allows an attacker with network access to execute arbitrary code on the server without authentication. Specifically, the vulnerability enables a malicious actor to send connection protocol messages before authentication takes place. Successful exploitation could lead to full compromise of the host, unauthorized access, manipulation of sensitive data, or denial-of-service attacks.

Description
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
Source
security-advisories@github.com
NVD status
Analyzed
Products
erlang\/otp, confd_basic, network_services_orchestrator, cloud_native_broadband_network_gateway, inode_manager, smart_phy, ultra_packet_core, ultra_services_platform, staros, optical_site_manager, ncs_2000_shelf_virtualization_orchestrator_firmware, enterprise_nfv_infrastructure_software, ultra_cloud_core, rv160w_firmware, rv260_firmware, rv160_firmware, rv260p_firmware, rv260w_firmware, rv340_firmware, rv340w_firmware, rv345_firmware, rv345p_firmware, debian_linux

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability
Exploit added on
Jun 9, 2025
Exploit action due
Jun 30, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

security-advisories@github.com
CWE-306

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2025-32433: Critical 10.0 CVSS Erlang/OTP SSH Server Pre-Auth RCE https://t.co/CQoH8PryTP #Cybersecurity #Infosec #AppSec #RCE #Erlang #OTP #SSH #CVE202532433 #PoC #EthicalHacking #BugBounty #PatchNow https://t.co/NcyvlcdIuv

    @r0otk3r

    12 Jul 2026

    38 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 23.05.2026 Erlang/OTP SSH: CVE-2025-32433 https://t.co/bNqhNucmdr

    @jubairbd007

    23 May 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. I just completed Erlang/OTP SSH: CVE-2025-32433 room on TryHackMe! Learn about and exploit Erlang/OTP SSH CVE-2025-32433 in a lab setup. https://t.co/7yoMbVNNro #tryhackme via @tryhackme #tryhackme #Learning #Consistency

    @LittleSun4lower

    8 May 2026

    251 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. A critical vulnerability in the Erlang/OTP SSH, tracked as CVE-2025-32433, has been disclosed that allows for unauthenticated remote code execution on vulnerable devices. [...] https://t.co/L6zk7qhwPR

    @hugo4tech

    15 Mar 2026

    143 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. I just completed Erlang/OTP SSH: CVE-2025-32433 room on TryHackMe! Learn about and exploit Erlang/OTP SSH CVE-2025-32433 in a lab setup. https://t.co/m6q6XkcwTY #tryhackme via @tryhackme

    @ToTo13ru_xakep

    7 Mar 2026

    156 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. How I Used AI to Create a Working Exploit for CVE-2025-32433 Before Public PoCs Existed - Matthew Keeley https://t.co/kuUyUGOo8l

    @pentest_swissky

    16 Feb 2026

    5570 Impressions

    8 Retweets

    88 Likes

    69 Bookmarks

    0 Replies

    0 Quotes

  7. HackTheBox - Soulmate 💥 Authentication Bypass en CrushFTP 🚀 RCE en Erlang/OTP SSH - CVE-2025-32433 https://t.co/mC4agnn2A8

    @sckull_

    15 Feb 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. New HackTheBox walkthrough: Soulmate CrushFTP exploitation → Erlang process analysis → CVE-2025-32433 privilege escalation to root. Full chain from subdomain enum to root shell. https://t.co/P9SUdqQkxT #HackTheBox #OSCP #CVE2025 https://t.co/F5BGufpFyT

    @Strikoder

    14 Feb 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. I just completed Erlang/OTP SSH: CVE-2025-32433 room on TryHackMe! Learn about and exploit Erlang/OTP SSH CVE-2025-32433 in a lab setup. https://t.co/xHYEmM7fsj #tryhackme via @tryhackme

    @Shyam48973Yadav

    20 Jan 2026

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. We reviewed the specific vulnerabilities that shaped attacker behavior in 2025: 1️⃣React2Shell (CVE-2025-55182) 2️⃣SAP NetWeaver (CVE-2025-31324) 3️⃣PAN-OS Auth Bypass (CVE-2025-0108) 4️⃣Cisco IOS XE (CVE-2025-20188) 5️⃣Erlang/OTP SSH (CVE-2025-32433) Full b

    @pdiscoveryio

    10 Jan 2026

    3532 Impressions

    12 Retweets

    69 Likes

    34 Bookmarks

    1 Reply

    0 Quotes

  11. Day 78 of #100DaysOfCybersecurity🛡️ Erlang OTP SSH CVE-2025-32433 lab completed ✅ Explored a CVSS 10.0 unauthenticated RCE in Erlang OTP SSH caused by improper pre-auth SSH message handling ⚠️ Key points 👇 • Exploitable before authentication • No reliable SSH

    @HezyChacha

    30 Dec 2025

    44 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 CVE-2025-32433 Vulnerability in Erlang/OTP SSH Implementation ⚠️ Only for educational purposes & ethical hacking 👍 Like, comment & share if this helped! #CyberSecurity #EthicalHacking #CVE #Exploit #PoC #RedTeam #BugBounty #Infosec #Pentesting #OSCP https://t.

    @r0otk3r

    28 Dec 2025

    96 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. cve-2025-32433_rce_exploit #exploit #scanner This exploit script is designed to simplify exploitation of the Erlang/OTP SSH vulnerability CVE-2025-32433 in the TryHackMe lab environment. https://t.co/Hv4aZrkSRa

    @TheExploitLab

    25 Dec 2025

    186 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. OT Networks Targeted in Widespread Exploitation of Erlang/OTP Vulnerability The recently patched Erlang/OTP flaw CVE-2025-32433 has been exploited since early May, shortly after its existence came to light. The post OT Networks Targeted in Widespread Exploitation of Erlang/OT...

    @SecurityAid

    15 Nov 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. I just completed Erlang/OTP SSH: CVE-2025-32433 room on TryHackMe. Learn about and exploit Erlang/OTP SSH CVE-2025-32433 in a lab setup. https://t.co/WhIpi5xkvm #tryhackme @tryhackmeより

    @yoshi_prog

    26 Oct 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. How does CVE-2025-32433 (Erlang SSH OTP Library) Vulnerability works? https://t.co/7vOWrOziJq

    @hacktheclown

    18 Oct 2025

    89 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. I just completed Erlang/OTP SSH: CVE-2025-32433 room on TryHackMe. Learn about and exploit Erlang/OTP SSH CVE-2025-32433 in a lab setup. https://t.co/birIpCAzhZ #tryhackme 来自 @realtryhackme

    @GuanShanZhe

    29 Sept 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. I just completed Erlang/OTP SSH: CVE-2025-32433 room on TryHackMe. Learn about and exploit Erlang/OTP SSH CVE-2025-32433 in a lab setup. https://t.co/PG3YIAhYOJ #tryhackme via @realtryhackme

    @yasirchandio12

    21 Sept 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. #VulnerabilityReport #CVE202532433 Critical Erlang/OTP Flaw (CVE-2025-32433) Under Active Exploitation, Allowing Unauthenticated RCE on OT Networks https://t.co/CFutFE7q8F

    @Komodosec

    16 Sept 2025

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. How I Used AI to Create a Working Exploit for CVE-2025-32433 Before Public PoCs Existed - Matthew Keeley https://t.co/kuUyUGOVXT

    @pentest_swissky

    11 Sept 2025

    1970 Impressions

    5 Retweets

    20 Likes

    12 Bookmarks

    1 Reply

    0 Quotes

  21. 🚨 "Keys to the Kingdom" via Erlang/OTP SSH? Palo Alto Networks Unit 42 reveals CVE-2025-32433 exploits *observed in the wild*! Critical vulnerability analysis you can't miss. #CyberSecurity #Vulnerability https://t.co/aoFXtJLy2z

    @xcybersecnews

    1 Sept 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. GPT-4 助攻資安研究!成功在 CVE-2025-32433 公開 Proof-of-Concept (概念驗證) 前,發現漏洞、生成 Exploit (漏洞利用程式) 並除錯。AI 潛力令人矚目。#AI #資安 https://t.co/Zq07QNnHjK

    @artofcryptowar

    31 Aug 2025

    119 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Erlang/OTP SSH の脆弱性 CVE-2025-32433:OT ネットワークへの活発な攻撃を検知 https://t.co/LeUTpJ7RN0 Erlang/OTP の SSH

    @iototsecnews

    25 Aug 2025

    132 Impressions

    2 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. ⚠️ Erlang/OTP SSH Flaw Enables Remote Code Execution Without Authentication https://t.co/v9ekJqsObC A critical vulnerability (CVE-2025-32433) in Erlang’s native SSH server allows unauthenticated attackers to execute commands remotely, by sending specially crafted SSH prot

    @Huntio

    23 Aug 2025

    4640 Impressions

    10 Retweets

    13 Likes

    5 Bookmarks

    1 Reply

    1 Quote

  25. Unauthenticated Remote Code Execution in Erlang/OTP SSH Server (CVE-2025-32433) https://t.co/pjo1LzXV9T https://t.co/4BJU1pleS9

    @Hack32_

    22 Aug 2025

    610 Impressions

    0 Retweets

    9 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  26. CVE-2025-32433 is a critical (CVSS 10.0) unauthenticated RCE vulnerability in Erlang/OTP sshd. Unit 42 discusses its impacts across critical infrastructure and especially operational technology (OT) networks. https://t.co/38W4lHbtYW

    @JackPen6

    17 Aug 2025

    39 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  27. CVE-2025-32433 is a critical (CVSS 10.0) unauthenticated RCE vulnerability in Erlang/OTP sshd. We discuss its impacts across critical infrastructure and especially operational technology (OT) networks: https://t.co/aCIgEI025g https://t.co/qKPr0VjTaH

    @Unit42_Intel

    14 Aug 2025

    9641 Impressions

    33 Retweets

    108 Likes

    34 Bookmarks

    1 Reply

    1 Quote

  28. OT angle — Erlang/OTP flaw hitting industrial networks OT teams: heads up. Palo Alto saw widespread exploitation of CVE-2025-32433 targeting OT networks. If you’ve got Erlang/OTP SSH exposed (often on 2222), patch to OTP-27.3.3 / 26.2.5.11 / 25.3.2.20 and lock down remote acc

    @PravinK_Goudar

    14 Aug 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. A terrifying vulnerability, CVE-2025-32433, has been exploited in the wild, affecting Erlang’s OTP due to a flaw in the SSH daemon. This remote code execution vulnerability primarily targets OT firewalls, posing a significant threat to critical infrastructure and safety, with .

    @CybrPulse

    13 Aug 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  30. Critical Erlang/OTP Flaw (CVE-2025-32433) Actively Exploited, Poses Major Threat to Industrial Networks https://t.co/H4eRD2aTAE

    @Daily_CyberSec

    13 Aug 2025

    288 Impressions

    2 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  31. CVE-2025-32433, a vulnerability in Erlang/OTP, and part of the CISA KEV, is now being actively exploited. According to #Unit42, this can have significant impact on OT networks which rely heavily on Erlang/OTP. Several IOCs listed in the writeup: https://t.co/uBJKoNXRgo

    @ct_is

    12 Aug 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. Researchers report a surge in Erlang/OTP SSH RCE exploits, with 70% targeting OT firewalls, stemming from a critical vulnerability (CVE-2025-32433) that has been actively abused since May 2025. #CyberSecurity #ExploitAlert https://t.co/a7OabtoP0X

    @Cyber_O51NT

    12 Aug 2025

    270 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  33. Palo Alto warns of OT-targeted exploitation of critical Erlang/OTP SSH vulnerability https://t.co/qBFfF03Y7w Palo Alto Networks reported active exploitation attempts targeting CVE-2025-32433, a critical vulnerability that enables unauthenticated remote code execution (RCE) in

    @f1tym1

    12 Aug 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. 【重要インフラへの脅威】Erlang/OTPのSSHデーモンに発見された致命的な脆弱性CVE-2025-32433が、世界中の産業制御システムを標的とした攻撃で悪用されている。Unit 42の調査によると、CVSS

    @nakajimeeee

    12 Aug 2025

    366 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. A critical remote code execution vulnerability in Erlang/OTP's SSH daemon, CVE-2025-32433, is being exploited against operational technology networks, affecting essential services. In a striking revelation, exploitation attempts surged by 160 percent on OT devices, highlightin...

    @CybrPulse

    12 Aug 2025

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  36. CVE-2025-32433: #Vulnerability in #Erlang/OTP #SSH Implementation https://t.co/ebipp8bgon https://t.co/5lx2VpMmTF

    @omvapt

    12 Aug 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. Erlang/OTP SSH daemon vulnerable to CVE-2025-32433 allows unauthenticated RCE via post-auth SSH messages. Exploits surged in May 2025, targeting OT firewalls in education, healthcare & tech sectors. Patches released. #CVE202532433 #ErlangOTP #USA https://t.co/jtHWJoMHet

    @TweetThreatNews

    11 Aug 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. Critical flaw CVE-2025-32433 in Erlang/OTP SSH enables remote code execution, with 70% of attacks targeting OT firewalls across healthcare, agriculture, media, and high tech. Patched April 2025. #ErlangOTP #OTSecurity #USA https://t.co/CLH3POkwaz

    @TweetThreatNews

    11 Aug 2025

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. Critical CVE-2025-32433 vulnerability in Erlang/OTP SSH exposes major security risk. Urgent patching needed. Monitoring shows rise in OT network incidents. https://t.co/pd5FYPIACF #CyberSecurity

    @threatlight

    11 Aug 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. 🚨 Critical flaw in Erlang/OTP’s SSH (CVE-2025-32433) is being actively exploited — no credentials needed, full remote code execution possible. Targets? Mostly OT networks — healthcare, agriculture, media, and high-tech sectors hit hardest. Here’s w... https://t.co/jJ

    @IT_news_for_all

    11 Aug 2025

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. 🚨 Critical flaw in Erlang/OTP’s SSH (CVE-2025-32433) is being actively exploited — no credentials needed, full remote code execution possible. Targets? Mostly OT networks — healthcare, agriculture, media, and high-tech sectors hit hardest. Here’s why it’s a global

    @TheHackersNews

    11 Aug 2025

    17715 Impressions

    77 Retweets

    198 Likes

    34 Bookmarks

    8 Replies

    1 Quote

  42. CVE-2025-32433 poses a critical security risk, enabling unauthenticated remote code execution in vulnerable Erlang/OTP SSH daemons used widely in industrial settings. Recent findings indicate that exploit attempts surged significantly, especially targeting operational technolo...

    @CybrPulse

    11 Aug 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  43. This week, Disclosed. #BugBounty My projects featured on Critical Thinking, $1M WhatsApp Bounty, AI Exploit for CVE-2025-32433, Bug Bounty Village CTF Prizes, and More. Full issue → https://t.co/Affe2Yws7J Highlights below 👇 @infinitelogins and @arl_rose discuss building

    @infinitelogins

    3 Aug 2025

    1480 Impressions

    3 Retweets

    28 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  44. ⚠️ Weekly vuln radar — https://t.co/Cd6L8ACyLV: CVE-2025-53770 — Sharepoint Server 📈⬆️ CVE-2025-32433 (@lambdafu) CVE-2025-25257 (@0x_shaq) CVE-2025-49113 (@k_firsov) CVE-2025-6558 (@_clem1) CVE-2025-30406 CVE-2025-54309 CVE-2025-23266 (@nirohfeld @shirtamari) CVE

    @ptdbugs

    1 Aug 2025

    160 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  45. 🧨🔥 CVE-2025-32433 | SSH Pre-Authentication RCE in Erlang/OTP: Exploit from Scratch + Real-World Proof of Concept on Arch Linux (Black Hat Style) video on my YouTube channel subscribe https://t.co/orLCEktHDz

    @Z3R0NYX

    31 Jul 2025

    215 Impressions

    1 Retweet

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. 🧨🔥 CVE-2025-32433 | SSH Pre-Authentication RCE in Erlang/OTP: Exploit from Scratch + Real-World Proof of Concept on Arch Linux (Black Hat Style) video on my YouTube channel subscribe https://t.co/G7aCBoBHNz https://t.co/UjRGFy7ppv

    @Z3R0NYX

    31 Jul 2025

    882 Impressions

    0 Retweets

    9 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  47. If you're learning about vibe hacking, here's a cool article demonstrating how @mattrkeeley used AI to create a working exploit for CVE-2025-32433 before any public PoCs existed! Worth a read 👇 https://t.co/74ALoE8V48 https://t.co/gVNhYNLC2M

    @0xacb

    31 Jul 2025

    6270 Impressions

    29 Retweets

    137 Likes

    107 Bookmarks

    2 Replies

    0 Quotes

  48. Erlang/OTP SSH al descubierto: CVE-2025-32433 (CVSS 10.0) RCE pre-auth. Parchéalo YA. 😉 #CVE2025 #Erlang #BugBounty https://t.co/IqIzHXJRsR

    @gorkaelbochi

    8 Jul 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. 🚨 STRIKE Threat Intel Advisory – CVE-2025-32433 🚨 SecurityScorecard’s STRIKE team is tracking active exposure of CVE-2025-6543 — a critical-severity vulnerability affecting Citrix Netscaler Application Delivery Controller with a CVSS score of 9.2. On June 30, 2025

    @security_score

    1 Jul 2025

    175 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  50. Top 5 Trending CVEs: 1 - CVE-2025-32711 2 - CVE-2024-51978 3 - CVE-2025-6430 4 - CVE-2025-32433 5 - CVE-2020-9547 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    29 Jun 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations