← Vulnerability feed

Vulnerability record · CVE-2025-32433 · published 16 April 2025

CVE-2025-32433: Erlang/OTP SSH server missing authentication allows remote code execution

Erlang · Erlang\/Otp

Erlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execute arbitrary commands. Because the SSH service is network-facing and no credentials are required, any exposed instance is at immediate risk. The flaw is a missing authentication check for a critical function (CWE-306).

10.0 CVSS 3.1 Critical CISA KEV since 9 Jun 2025 EPSS 99% · top 0.1% CWE-306 · Missing authentication for critical function
10.0CVSS 3.1 base score
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
23Affected product versions listed by NVD
14References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with CVSS 10.0, KEV listing and near-certain EPSS probability makes this an urgent patch-first issue.

What it is

Erlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execute arbitrary commands. Because the SSH service is network-facing and no credentials are required, any exposed instance is at immediate risk. The flaw is a missing authentication check for a critical function (CWE-306).

Impact

An attacker gains unauthenticated remote code execution on the affected host, allowing arbitrary command execution and full compromise of the service account and reachable data. CVSS 3.1 base score is 10.0 (critical), reflecting scope change and high confidentiality, integrity and availability impact.

Attack surface

Reachable over the network via the SSH service (AV:N, PR:N, UI:N); no authentication or user interaction is needed. Any Erlang/OTP SSH listener exposed to untrusted networks is in scope, including embedded products that ship the affected OTP versions.

Exploitation

CVE-2025-32433 is listed in CISA KEV (added 2025-06-09, due 2025-06-30) and has a public exploit reference, and EPSS 30-day probability is 0.98754 (99.9th percentile), indicating active exploitation is expected. KEV notes no known ransomware campaign use.

What to do

  • Upgrade Erlang/OTP to OTP-27.3.3, OTP-26.2.5.11 or OTP-25.3.2.20 (or later) as the primary fix.
  • If patching is not immediately possible, disable the Erlang/OTP SSH server or block access to its port with firewall rules.
  • Apply vendor-specific updates for products embedding affected OTP versions (Cisco, Debian and others listed in advisories).
  • Restrict SSH listener exposure to trusted management networks and remove internet-facing instances.
  • Track CISA KEV remediation deadlines (due 2025-06-30) and verify patched versions across all deployments.

Detection

  • Monitor SSH service logs for anomalous protocol message sequences or connections that reach command execution without successful authentication.
  • Alert on unexpected outbound connections or process spawning from Erlang/OTP SSH service accounts.
  • Inventory hosts running Erlang/OTP SSH listeners and compare versions against the fixed releases.
  • Hunt for exploitation attempts using the public proof-of-concept behavior against exposed SSH endpoints in network telemetry.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-32433 to the Known Exploited Vulnerabilities catalog on 9 June 2025 as "Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 30 June 2025.

Affected products

23 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-32433 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2022-20777Cisco enterprise nfv infrastructure software improper access control vulnerabilityMultiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM…EPSS 11%9.8CVE-2021-34746Cisco enterprise nfv infrastructure software improper authentication vulnerabilityA vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) cou…EPSS 18%9.8CVE-2020-3470Cisco enterprise nfv infrastructure software memory buffer overflow vulnerabilityMultiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to exec…EPSS 4.8%9.8CVE-2019-1971Cisco enterprise nfv infrastructure software os command injection vulnerabilityA vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform …EPSS 3.6%9.8CVE-2019-1895Cisco enterprise nfv infrastructure software missing authentication for critical function vulnerabilityA vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an …EPSS 2.3%8.8CVE-2022-20779Cisco enterprise nfv infrastructure software improper access control vulnerabilityMultiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM…EPSS 10%8.8CVE-2018-0279Cisco enterprise nfv infrastructure software improper input validation vulnerabilityA vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote…EPSS 4.4%8.1CVE-2020-3478Cisco enterprise nfv infrastructure software improper input validation vulnerabilityA vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to overwrite ce…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2025-32433), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.