Vulnerability record · CVE-2025-32433 · published 16 April 2025
CVE-2025-32433: Erlang/OTP SSH server missing authentication allows remote code execution
Erlang · Erlang\/Otp
Erlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execute arbitrary commands. Because the SSH service is network-facing and no credentials are required, any exposed instance is at immediate risk. The flaw is a missing authentication check for a critical function (CWE-306).
Description
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with CVSS 10.0, KEV listing and near-certain EPSS probability makes this an urgent patch-first issue.
What it is
Erlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execute arbitrary commands. Because the SSH service is network-facing and no credentials are required, any exposed instance is at immediate risk. The flaw is a missing authentication check for a critical function (CWE-306).
Impact
An attacker gains unauthenticated remote code execution on the affected host, allowing arbitrary command execution and full compromise of the service account and reachable data. CVSS 3.1 base score is 10.0 (critical), reflecting scope change and high confidentiality, integrity and availability impact.
Attack surface
Reachable over the network via the SSH service (AV:N, PR:N, UI:N); no authentication or user interaction is needed. Any Erlang/OTP SSH listener exposed to untrusted networks is in scope, including embedded products that ship the affected OTP versions.
Exploitation
CVE-2025-32433 is listed in CISA KEV (added 2025-06-09, due 2025-06-30) and has a public exploit reference, and EPSS 30-day probability is 0.98754 (99.9th percentile), indicating active exploitation is expected. KEV notes no known ransomware campaign use.
What to do
- Upgrade Erlang/OTP to OTP-27.3.3, OTP-26.2.5.11 or OTP-25.3.2.20 (or later) as the primary fix.
- If patching is not immediately possible, disable the Erlang/OTP SSH server or block access to its port with firewall rules.
- Apply vendor-specific updates for products embedding affected OTP versions (Cisco, Debian and others listed in advisories).
- Restrict SSH listener exposure to trusted management networks and remove internet-facing instances.
- Track CISA KEV remediation deadlines (due 2025-06-30) and verify patched versions across all deployments.
Detection
- Monitor SSH service logs for anomalous protocol message sequences or connections that reach command execution without successful authentication.
- Alert on unexpected outbound connections or process spawning from Erlang/OTP SSH service accounts.
- Inventory hosts running Erlang/OTP SSH listeners and compare versions against the fixed releases.
- Hunt for exploitation attempts using the public proof-of-concept behavior against exposed SSH endpoints in network telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-32433 to the Known Exploited Vulnerabilities catalog on 9 June 2025 as "Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 30 June 2025.
Affected products
23 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-32433 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-32433), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.