logo

Keys to the Kingdom: Erlang/OTP SSH Vulnerability Analysis and Exploits Observed in the Wild

ID: 01dd426b-4ab7-501c-a7aa-f436e8fa97b0

STIX ID: report--01dd426b-4ab7-501c-a7aa-f436e8fa97b0

Feed Name: Palo Alto Networks Unit 42

Threat Score
85/100

Date Published: 2025-08-11

Date Updated: 2026-04-28

Author: Adam Robbie, Yiheng An, Malav Vyas, Cecilia Hu, Matthew Tennis, Hugo Perez, Zhanhao Chen and Rick Wyble

...
...

This Unit 42 report documents active exploitation of CVE-2025-32433, an unauthenticated RCE in Erlang/OTP's sshd (CVSS 10.0). Telemetry from April–May 2025 shows hundreds of exposed Erlang/OTP services and 3,376 exploit signature triggers (≈70% from OT firewalls) with reverse-shell payloads and DNS-based OOB callbacks; the report lists IoCs, affected industries and geographies, and urges immediate patching to OTP-27.3.3/26.2.5.11/25.3.2.20 or network-based mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.