logo

CVE-2025-32433: Unauthenticated RCE Vulnerability in Erlang/OTP’s SSH Implementation

ID: 97053747-0a63-5f94-a76d-de2c3485a036

STIX ID: report--97053747-0a63-5f94-a76d-de2c3485a036

Feed Name: Cybereason Blog

Threat Score
95/100

Date Published: 2025-04-20

Date Updated: 2026-04-27

Author: Cybereason Consulting Team

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2025-32433, CVSS 10.0) was disclosed in the Erlang/OTP SSH server that lets attackers send out-of-order SSH messages during the handshake to execute arbitrary commands with the SSH daemon's privileges. Public PoCs appeared quickly, the flaw affects any product embedding OTP's SSH (telecom gear, IoT, RabbitMQ, etc.), and immediate patching or disabling/restricting the OTP SSH service is strongly recommended to prevent full system compromise and likely mass exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.