CVE-2025-32433
critical · 10Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| erlang | erlang/otp | < 25.3.2.20 |
| erlang | erlang/otp | >= 26.0, < 26.2.5.11 |
| erlang | erlang/otp | >= 27.0, < 27.3.3 |
| cisco | confd_basic | < 7.7.19.1 |
| cisco | confd_basic | >= 8.0.18, < 8.1.16.2 |
| cisco | confd_basic | >= 8.2, < 8.2.11.1 |
| cisco | confd_basic | >= 8.3, < 8.3.8.1 |
| cisco | confd_basic | >= 8.4, < 8.4.4.1 |
| cisco | network_services_orchestrator | < 5.7.19.1 |
| cisco | network_services_orchestrator | >= 5.8, < 6.1.16.2 |
| cisco | network_services_orchestrator | >= 6.2, < 6.2.11.1 |
| cisco | network_services_orchestrator | >= 6.3, < 6.3.8.1 |
| cisco | network_services_orchestrator | >= 6.4, < 6.4.1.1 |
| cisco | network_services_orchestrator | >= 6.4.2, < 6.4.4.1 |
| cisco | cloud_native_broadband_network_gateway | < 2025.03.1 |
| cisco | inode_manager | all versions |
| cisco | smart_phy | < 25.2 |
| cisco | ultra_packet_core | < 2025.03 |
| cisco | ultra_services_platform | all versions |
| cisco | staros | < 2025.03 |
| cisco | optical_site_manager | < 25.2.1 |
| cisco | ncs_1001 | all versions |
| cisco | ncs_1002 | all versions |
| cisco | ncs_1004 | all versions |
| cisco | ncs_2000_shelf_virtualization_orchestrator_firmware | < 25.1.1 |
| cisco | ncs_2000_shelf_virtualization_orchestrator_module | all versions |
| cisco | enterprise_nfv_infrastructure_software | < 4.18 |
| cisco | ultra_cloud_core | < 2025.03.1 |
| cisco | rv160w_firmware | all versions |
| cisco | rv160w | all versions |
| cisco | rv260_firmware | all versions |
| cisco | rv260 | all versions |
| cisco | rv160_firmware | all versions |
| cisco | rv160 | all versions |
| cisco | rv260p_firmware | all versions |
| cisco | rv260p | all versions |
| cisco | rv260w_firmware | all versions |
| cisco | rv260w | all versions |
| cisco | rv340_firmware | all versions |
| cisco | rv340 | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/erlang/otp/commit/0fcd9c56524b28615e8ece65fc0c3f66ef6e4c12
- https://github.com/erlang/otp/commit/6eef04130afc8b0ccb63c9a0d8650209cf54892f
- https://github.com/erlang/otp/commit/b1924d37fd83c070055beb115d5d6a6a9490b891
- https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2
- http://www.openwall.com/lists/oss-security/2025/04/16/2
- http://www.openwall.com/lists/oss-security/2025/04/18/1
- http://www.openwall.com/lists/oss-security/2025/04/18/2
- http://www.openwall.com/lists/oss-security/2025/04/18/6
- http://www.openwall.com/lists/oss-security/2025/04/19/1
- https://lists.debian.org/debian-lts-announce/2025/04/msg00028.html
- https://security.netapp.com/advisory/ntap-20250425-0001/
- https://github.com/ProDefense/CVE-2025-32433/blob/main/CVE-2025-32433.py
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-erlang-otp-ssh-xyZZy
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32433
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-32433