PT-2025-16905 · Ericsson+7 · Erlang/Otp+7
Lambdafu
+1
·
Published
2025-04-16
·
Updated
2026-07-12
·
CVE-2025-32433
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Erlang/OTP versions prior to OTP-27.3.3
Erlang/OTP versions prior to OTP-26.2.5.11
Erlang/OTP versions prior to OTP-25.3.2.20
Description
An issue in the SSH protocol message handling of the Erlang/OTP SSH server allows an unauthenticated remote attacker to perform remote code execution (RCE). The flaw occurs because the server may fail to verify the authentication stage and incorrectly process
CHANNEL OPEN and exec requests immediately after the TCP connection and key exchange initialization, allowing arbitrary commands to be executed without valid credentials. This issue has been exploited in the wild, with significant targeting of operational technology (OT) networks, including healthcare, agriculture, and high-tech sectors. It is estimated that over 600,000 IP addresses running Erlang/OTP are potentially affected worldwide.Recommendations
Update to version OTP-27.3.3 or newer.
Update to version OTP-26.2.5.11 or newer.
Update to version OTP-25.3.2.20 or newer.
As a temporary workaround, disable the SSH server or restrict access using firewall rules.
Exploit
Fix
LPE
RCE
DoS
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Erlang/Otp
Linuxmint
Red Os
Suse
Ubuntu