CVE-2025-32433 is a critical unauthenticated remote code execution (RCE) vulnerability in Erlang/OTP's SSH server, affecting versions prior to OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, including products from Cisco and Debian. This flaw allows attackers to execute arbitrary commands without credentials by exploiting a weakness in SSH protocol message handling. With a CVSS score of 10.0, the vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. This CVE is actively exploited in the wild, has public exploit modules available in Metasploit and Nuclei, and has garnered significant community and media attention, indicating a high risk of compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 25.3.2.20CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* | ||
>= 26.0, < 26.2.5.11CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* | ||
>= 27.0, < 27.3.3CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* | ||
< 7.7.19.1CPE matchmatch criteria | cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:* | ||
>= 8.0.18, < 8.1.16.2CPE matchmatch criteria | cpe:2.3:a:cisco:confd_basic:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.