← Back to CVE intelligence
CVE intelligenceCISA KEV

CVE-2025-32433

Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability

Published Apr 16, 2025Sources checked Oct 9, 2026
10.0CRITICALCVSS out of 10
What this means

Actively exploited

CISA lists CVE-2025-32433 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Erlang Erlang/OTP.

  • Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Public exploit: Cataloged public exploit.

What to do next

Remediation and response

Microsoft Security Response Center guidance

Vendor revision: Aug 12, 2026

CBL-Mariner Releases

Vendor-listed releases

  • 26.2.5.11-1
  • 25.3.2.20-1
CISA KEVListedObserved exploitation
EPSS98.8%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2025-32433?

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE).

By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20.

A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

Source: NVD

CISA says:Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.CISA catalog due date Jun 30, 2025