logo

CVE-2025-32433: Maximum Severity Unauthenticated RCE Vulnerability in Erlang/OTP SSH

ID: 86fa7655-f1f7-53c7-9705-4c2e9c21e407

STIX ID: report--86fa7655-f1f7-53c7-9705-4c2e9c21e407

Feed Name: Arctic Wolf

Threat Score
88/100

Date Published: 2025-04-21

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

On April 16, 2025 a critical vulnerability (CVE-2025-32433) in Erlang/OTP SSH was disclosed that allows unauthenticated remote code execution by sending protocol messages before authentication; public PoC exploits and technical writeups were released shortly after, and many Erlang-dependent products (including networking, ICS/OT, and server software) may be affected. The advisory recommends upgrading to patched Erlang/OTP releases or, if unavailable, disabling the SSH server or restricting access while vendors release product-specific updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.