CVE-2025-32433
Last modified
CVE-2025-32433 is a critical-severity vulnerability rated 10/10 on the CVSS scale. Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). CISA has confirmed active exploitation in the wild. EPSS estimates a 97.67% chance of exploitation in the next 30 days.
Description
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Erlang | Erlang\/Otp | < 25.3.2.20 |
| Erlang | Erlang\/Otp | >= 26.0, < 26.2.5.11 |
| Erlang | Erlang\/Otp | >= 27.0, < 27.3.3 |
| Cisco | Confd Basic | < 7.7.19.1 |
| Cisco | Confd Basic | >= 8.0.18, < 8.1.16.2 |
| Cisco | Confd Basic | >= 8.2, < 8.2.11.1 |
| Cisco | Confd Basic | >= 8.3, < 8.3.8.1 |
| Cisco | Confd Basic | >= 8.4, < 8.4.4.1 |
| Cisco | Network Services Orchestrator | < 5.7.19.1 |
| Cisco | Network Services Orchestrator | >= 5.8, < 6.1.16.2 |
| Cisco | Network Services Orchestrator | >= 6.2, < 6.2.11.1 |
| Cisco | Network Services Orchestrator | >= 6.3, < 6.3.8.1 |
| Cisco | Network Services Orchestrator | >= 6.4, < 6.4.1.1 |
| Cisco | Network Services Orchestrator | >= 6.4.2, < 6.4.4.1 |
| Cisco | Cloud Native Broadband Network Gateway | < 2025.03.1 |
| Cisco | Inode Manager | All versions |
| Cisco | Smart Phy | < 25.2 |
| Cisco | Ultra Packet Core | < 2025.03 |
| Cisco | Ultra Services Platform | All versions |
| Cisco | Staros | < 2025.03 |
| Cisco | Optical Site Manager | < 25.2.1 |
| Cisco | Ncs 2000 Shelf Virtualization Orchestrator Firmware | < 25.1.1 |
| Cisco | Enterprise Nfv Infrastructure Software | < 4.18 |
| Cisco | Ultra Cloud Core | < 2025.03.1 |
| Cisco | Rv160w Firmware | All versions |
| Cisco | Rv260 Firmware | All versions |
| Cisco | Rv160 Firmware | All versions |
| Cisco | Rv260p Firmware | All versions |
| Cisco | Rv260w Firmware | All versions |
| Cisco | Rv340 Firmware | All versions |
| Cisco | Rv340w Firmware | All versions |
| Cisco | Rv345 Firmware | All versions |
| Cisco | Rv345p Firmware | All versions |
| Debian | Debian Linux | 11.0 |
References
- https://lists.debian.org/debian-lts-announce/2025/04/msg00028.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20250425-0001/Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32433US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-32433?
How severe is CVE-2025-32433?
How do I fix CVE-2025-32433?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-32428Jupyter Remote Desktop Proxy allows you to run a Linux Deskt…9
- CVE-2025-32429XWiki Platform is a generic wiki platform offering runtime s…9.8
- CVE-2025-3243A vulnerability was found in code-projects Patient Record Ma…8.8
- CVE-2025-32430XWiki Platform is a generic wiki platform offering runtime s…6.1
- CVE-2025-32431Traefik (pronounced traffic) is an HTTP reverse proxy and lo…9.1
- CVE-2025-32432Craft is a flexible, user-friendly CMS for creating custom d…10
- CVE-2025-32434PyTorch is a Python package that provides tensor computation…9.8
- CVE-2025-32435Hydra is a Continuous Integration service for Nix based proj…2.6
- CVE-2025-32436AutoGPT is a workflow automation platform for creating, depl…7.1
- CVE-2025-32437AutoGPT is a workflow automation platform for creating, depl…8.7
- CVE-2025-32438make-initrd-ng is a tool for copying binaries and their depe…8.8
- CVE-2025-32439pleezer is a headless Deezer Connect player. Hook scripts in…6.5
Are you affected by CVE-2025-32433?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
