CVE-2025-32433: Unauthenticated RCE Vulnerability in Erlang/OTP’s SSH Implementation
ID: 97053747-0a63-5f94-a76d-de2c3485a036
STIX ID: report--97053747-0a63-5f94-a76d-de2c3485a036
Feed Name: Cybereason Blog
A critical unauthenticated remote code execution vulnerability (CVE-2025-32433, CVSS 10.0) was disclosed in the Erlang/OTP SSH server that lets attackers send out-of-order SSH messages during the handshake to execute arbitrary commands with the SSH daemon's privileges. Public PoCs appeared quickly, the flaw affects any product embedding OTP's SSH (telecom gear, IoT, RabbitMQ, etc.), and immediate patching or disabling/restricting the OTP SSH service is strongly recommended to prevent full system compromise and likely mass exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
