CVE-2025-32433: Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability
Critical severity, CVSS 10.0. Actively exploited: in CISA KEV since 2025-06-09. EPSS: 98.8% chance of exploitation in the next 30 days.
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
Affected products
- Cisco Cloud Native Broadband Network Gateway: before 2025.03.1 (fixed in 2025.03.1)
- Cisco Confd Basic: before 7.7.19.1 (fixed in 7.7.19.1); from 8.0.18, before 8.1.16.2 (fixed in 8.1.16.2); from 8.2, before 8.2.11.1 (fixed in 8.2.11.1); from 8.3, before 8.3.8.1 (fixed in 8.3.8.1); from 8.4, before 8.4.4.1 (fixed in 8.4.4.1)
- Cisco Enterprise Nfv Infrastructure Software: before 4.18 (fixed in 4.18)
- Cisco Inode Manager: affected versions not specified
- Cisco Ncs 2000 Shelf Virtualization Orchestrator Firmware: before 25.1.1 (fixed in 25.1.1)
- Cisco Network Services Orchestrator: before 5.7.19.1 (fixed in 5.7.19.1); from 5.8, before 6.1.16.2 (fixed in 6.1.16.2); from 6.2, before 6.2.11.1 (fixed in 6.2.11.1); from 6.3, before 6.3.8.1 (fixed in 6.3.8.1); from 6.4, before 6.4.1.1 (fixed in 6.4.1.1); from 6.4.2, before 6.4.4.1 (fixed in 6.4.4.1)
- Cisco Optical Site Manager: before 25.2.1 (fixed in 25.2.1)
- Cisco RV160 Firmware: affected versions not specified
- Cisco RV160W Firmware: affected versions not specified
- Cisco RV260 Firmware: affected versions not specified
- Cisco RV260P Firmware: affected versions not specified
- Cisco RV260W Firmware: affected versions not specified
- Cisco RV340 Firmware: affected versions not specified
- Cisco RV340W Firmware: affected versions not specified
- Cisco RV345 Firmware: affected versions not specified
- Cisco RV345P Firmware: affected versions not specified
- Cisco Smart Phy: before 25.2 (fixed in 25.2)
- Cisco Staros: before 2025.03 (fixed in 2025.03)
- Cisco Ultra Cloud Core: before 2025.03.1 (fixed in 2025.03.1)
- Cisco Ultra Packet Core: before 2025.03 (fixed in 2025.03)
- Cisco Ultra Services Platform: affected versions not specified
- Debian Debian Linux: version 11.0 only
- Erlang Erlang/otp: before 25.3.2.20 (fixed in 25.3.2.20); from 26.0, before 26.2.5.11 (fixed in 26.2.5.11); from 27.0, before 27.3.3 (fixed in 27.3.3)
Published 2025-04-16. Last modified 2026-06-17.