PT-2025-16905 · Ericsson+7 · Erlang/Otp+7

Lambdafu

+1

·

Published

2025-04-16

·

Updated

2026-05-08

·

CVE-2025-32433

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Erlang/OTP versions prior to 27.3.3 Erlang/OTP versions prior to 26.2.5.11 Erlang/OTP versions prior to 25.3.2.20
Description A critical flaw in the SSH server implementation of Erlang/OTP allows an unauthenticated remote attacker to achieve remote code execution (RCE). The issue stems from incorrect handling of the SSH protocol state, where the server fails to verify the authentication stage and may process CHANNEL OPEN and exec messages before authentication is completed. By sending specially crafted SSH packets, an attacker can execute arbitrary commands, potentially leading to full system compromise, especially if the SSH daemon runs with root privileges.
Approximately 600,000 IP addresses are estimated to be running Erlang/OTP, with significant exposure in telecom infrastructures, databases, and operational technology (OT) networks. Real-world exploitation has been observed, particularly targeting OT environments in the US, Brazil, France, Japan, and other regions. Attackers have used reverse shells and DNS callbacks to establish unauthorized access and move laterally within corporate networks to reach critical infrastructure.
Recommendations Update to version 27.3.3 or later. Update to version 26.2.5.11 or later. Update to version 25.3.2.20 or later. As a temporary workaround, disable the SSH server or restrict access using firewall rules.

Exploit

Fix

LPE

RCE

DoS

Missing Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6176
ALT-PU-2025-6402
AZL-60441
AZL-60583
BDU:2025-04706
CVE-2025-32433
DLA-4132-1
DSA-5906-1
ERLANG_CVE_2025_32433
GHSA-37CP-FGQ5-7WC2
OESA-2025-1461
OPENSUSE-SU-2025_1356-1
OPENSUSE-SU-2025_1357-1
SUSE-SU-2025:1356-1
SUSE-SU-2025:1357-1
SUSE-SU-2025_1356-1
SUSE-SU-2025_1357-1
USN-7443-1
USN-7443-2
USN-7443-3

Affected Products

Alt Linux
Astra Linux
Debian
Erlang/Otp
Linuxmint
Red Os
Suse
Ubuntu