Keys to the Kingdom: Erlang/OTP SSH Vulnerability Analysis and Exploits Observed in the Wild
ID: 01dd426b-4ab7-501c-a7aa-f436e8fa97b0
STIX ID: report--01dd426b-4ab7-501c-a7aa-f436e8fa97b0
Feed Name: Palo Alto Networks Unit 42
Date Published: 2025-08-11
Date Updated: 2026-04-28
Author: Adam Robbie, Yiheng An, Malav Vyas, Cecilia Hu, Matthew Tennis, Hugo Perez, Zhanhao Chen and Rick Wyble
This Unit 42 report documents active exploitation of CVE-2025-32433, an unauthenticated RCE in Erlang/OTP's sshd (CVSS 10.0). Telemetry from April–May 2025 shows hundreds of exposed Erlang/OTP services and 3,376 exploit signature triggers (≈70% from OT firewalls) with reverse-shell payloads and DNS-based OOB callbacks; the report lists IoCs, affected industries and geographies, and urges immediate patching to OTP-27.3.3/26.2.5.11/25.3.2.20 or network-based mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
