logo

CVE-2025-32433 - State Machine Err-ly RCE in Erlang/OTP SSH Server

ID: 814ea0f0-4576-51b2-b89b-6e272d4190a2

STIX ID: report--814ea0f0-4576-51b2-b89b-6e272d4190a2

Feed Name: GreyNoise Labs

Threat Score
75/100

Date Published: 2025-04-22

Date Updated: 2026-04-27

Author: Konstantin Lazarev

...
...

This report analyzes CVE-2025-32433 in Erlang/OTP's SSH server which allows unauthenticated SSH messages (channel open + channel request) to be processed and leads to remote code execution; it includes relevant Erlang source snippets, RFC references, a step-by-step reproduction on Ubuntu Jammy, and a Paramiko-based PoC that demonstrates successful RCE (creates a file), with vendor advisories (e.g., Cisco) referenced.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.