CVE-2025-32433
KEVCRITICAL 10.0EPSS 98.6%
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 98.59% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-06-09
- Nuclei
- critical · CWE-306
- Published
- 2025-04-16
- Updated
- 2026-02-26
Proof-of-concept exploits (38)
- 0x7556/CVE-2025-324333★ · 2026-06-07
- 0xPThree/cve-2025-324336★ · 2025-04-19
- Ba3a-G/erlang-ssh-bypass0★ · 2025-04-28
- Know56/CVE-2025-324331★ · 2025-04-28
- LemieOne/CVE-2025-324333★ · 2025-04-18
- Mdusmandasthaheer/CVE-2025-324330★ · 2025-08-28
- MrDreamReal/CVE-2025-324330★ · 2025-04-27
- NiteeshPujari/CVE-2025-32433-PoC7★ · 2025-08-14
- ODST-Forge/CVE-2025-32433_PoC0★ · 2025-05-13
- TeneBrae93/CVE-2025-32437★ · 2025-04-24
- abrewer251/CVE-2025-32433_Erlang-OTP_PoC1★ · 2025-05-13
- becrevex/CVE-2025-324331★ · 2025-05-08
- bilalz5-github/Erlang-OTP-SSH-CVE-2025-324331★ · 2025-05-02
- darses/CVE-2025-324333★ · 2025-04-19
- dollarboysushil/CVE-2025-32433-Erlang-OTP-SSH-Unauthenticated-RCE3★ · 2025-09-07
- ekomsSavior/POC_CVE-2025-324335★ · 2025-04-19
- exa-offsec/ssh_erlangotp_rce3★ · 2025-05-06
- iteride/CVE-2025-324331★ · 2025-09-21
- meloppeitreet/CVE-2025-32433-Remote-Shell0★ · 2025-04-21
- mirmeweu/cve-2025-324332★ · 2025-09-25
- omer-efe-curkus/CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC16★ · 2025-08-04
- platsecurity/CVE-2025-32433143★ · 2025-08-02
- teamtopkarl/CVE-2025-324331★ · 2025-04-19
- vigilante-1337/CVE-2025-324330★ · 2025-05-03
- 0xBlackash/CVE-2025-32433
- AntonieSoga/Erlang-OTP-PoC_CVE-2025-32433
- Batman529/PoC-CVE-2025-32433
- Liam-Worsley/CVE-2025-32433-PoC-Analysis
- ProDefense/CVE-2025-32433
- blackcat4347/CVE-2025-32433-available-for-windows
- chuzouX/CVE-2025-32433-Exploit-edited
- giriaryan694-a11y/cve-2025-32433_rce_exploit
- joshuavanderpoll/cve-2025-32433
- l1nuxkid/CVE-2025-32433-exploit
- razureink/cve-2025-32433-erlang_ssh_rce_reproduction
- soltanali0/CVE-2025-32433-Eploit
- toshithh/CVE-2025-32433
- yonathanpy/CVE-2025-32433.py