PT-2025-16905 · Ericsson+7 · Erlang/Otp+7

Lambdafu

+1

·

Published

2025-04-16

·

Updated

2026-06-22

·

CVE-2025-32433

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Erlang/OTP versions prior to OTP-27.3.3 Erlang/OTP versions prior to OTP-26.2.5.11 Erlang/OTP versions prior to OTP-25.3.2.20
Description A critical flaw in the SSH protocol implementation of the Erlang/OTP library allows unauthenticated remote code execution (RCE). The issue stems from incorrect handling of SSH protocol messages, where the server may fail to verify the authentication stage and prematurely process CHANNEL OPEN and exec requests. This enables a remote attacker to send specially crafted SSH packets to execute arbitrary commands without valid credentials. If the SSH daemon runs with root privileges, an attacker can gain full control of the host system. Approximately 600,000 IP addresses are estimated to be running Erlang/OTP, with significant risks to telecom infrastructures, databases, and high-availability systems. Real-world exploitation has been observed, particularly targeting operational technology (OT) networks, with some attacks focusing on healthcare, agriculture, media, and high-tech sectors in the US, Canada, Brazil, India, and Australia. Attackers have been seen deploying reverse shells to maintain unauthorized remote access.
Recommendations Update to version OTP-27.3.3 or newer. Update to version OTP-26.2.5.11 or newer. Update to version OTP-25.3.2.20 or newer. As a temporary workaround, disable the SSH server or restrict access using firewall rules.

Exploit

Fix

DoS

LPE

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6176
ALT-PU-2025-6402
AZL-60441
AZL-60583
BDU:2025-04706
CVE-2025-32433
DLA-4132-1
DSA-5906-1
ERLANG_CVE_2025_32433
GHSA-37CP-FGQ5-7WC2
OESA-2025-1461
OPENSUSE-SU-2025_1356-1
OPENSUSE-SU-2025_1357-1
SUSE-SU-2025:1356-1
SUSE-SU-2025:1357-1
SUSE-SU-2025_1356-1
SUSE-SU-2025_1357-1
USN-7443-1
USN-7443-2
USN-7443-3

Affected Products

Alt Linux
Astra Linux
Debian
Erlang/Otp
Linuxmint
Red Os
Suse
Ubuntu