CVE-2025-32433

CRITICAL CISA KEV
Published Apr 16, 2025 Modified Nov 4, 2025 CWE-306

Description

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

CVSS v3.1 Score

10.0
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild.

Added: Jun 9, 2025 Remediation due: Jun 30, 2025

Weakness Type (CWE)

CWE-306 Missing Authentication

Affected Products

Vendor Product
erlang erlang\/otp
erlang erlang\/otp
erlang erlang\/otp
cisco confd_basic
cisco confd_basic
cisco confd_basic
cisco confd_basic
cisco confd_basic
cisco network_services_orchestrator
cisco network_services_orchestrator
cisco network_services_orchestrator
cisco network_services_orchestrator
cisco network_services_orchestrator
cisco network_services_orchestrator
cisco cloud_native_broadband_network_gateway
cisco inode_manager
cisco smart_phy
cisco ultra_packet_core
cisco ultra_services_platform
cisco staros
cisco optical_site_manager
cisco ncs_1001
cisco ncs_1002
cisco ncs_1004
cisco ncs_2000_shelf_virtualization_orchestrator_firmware
cisco ncs_2000_shelf_virtualization_orchestrator_module
cisco enterprise_nfv_infrastructure_software
cisco ultra_cloud_core
cisco rv160w_firmware
cisco rv160w
cisco rv260_firmware
cisco rv260
cisco rv160_firmware
cisco rv160
cisco rv260p_firmware
cisco rv260p
cisco rv260w_firmware
cisco rv260w
cisco rv340_firmware
cisco rv340
cisco rv340w_firmware
cisco rv340w
cisco rv345_firmware
cisco rv345
cisco rv345p_firmware
cisco rv345p
debian debian_linux

References

Frequently Asked Questions

What is CVE-2025-32433? +
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules. It has a CVSS v3.1 base score of 10.0 (CRITICAL). This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.
How severe is CVE-2025-32433? +
CVE-2025-32433 has a CVSS v3.1 score of 10.0 out of 10, rated CRITICAL. This is a critical vulnerability that should be patched immediately.
What products are affected by CVE-2025-32433? +
CVE-2025-32433 affects products from cisco, debian, erlang, specifically: cloud_native_broadband_network_gateway, confd_basic, debian_linux, enterprise_nfv_infrastructure_software, erlang\/otp, inode_manager, ncs_1001, ncs_1002, ncs_1004, ncs_2000_shelf_virtualization_orchestrator_firmware, ncs_2000_shelf_virtualization_orchestrator_module, network_services_orchestrator, optical_site_manager, rv160, rv160_firmware, rv160w, rv160w_firmware, rv260, rv260_firmware, rv260p, rv260p_firmware, rv260w, rv260w_firmware, rv340, rv340_firmware, rv340w, rv340w_firmware, rv345, rv345_firmware, rv345p, rv345p_firmware, smart_phy, staros, ultra_cloud_core, ultra_packet_core, ultra_services_platform. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-32433? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-32433 — free, no signup required.

Start Free Scan