CVE-2025-32433

CRITICAL KEV NUCLEI

Erlang OTP Pre-Auth RCE Scanner and Exploit

Title source: metasploit

Description

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

Exploits (49)

nomisec WORKING POC 139 stars
by ProDefense · poc
https://github.com/ProDefense/CVE-2025-32433
nomisec WORKING POC 15 stars
by omer-efe-curkus · remote
https://github.com/omer-efe-curkus/CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC
github WORKING POC 7 stars
by TeneBrae93 · pythonremote
https://github.com/TeneBrae93/CVE-2025-3243
nomisec WORKING POC 6 stars
by NiteeshPujari · remote
https://github.com/NiteeshPujari/CVE-2025-32433-PoC
nomisec SCANNER 5 stars
by m0usem0use · poc
https://github.com/m0usem0use/erl_mouse
nomisec WORKING POC 5 stars
by 0xPThree · remote
https://github.com/0xPThree/cve-2025-32433
nomisec WORKING POC 4 stars
by ekomsSavior · remote
https://github.com/ekomsSavior/POC_CVE-2025-32433
nomisec WORKING POC 3 stars
by 0x7556 · poc
https://github.com/0x7556/CVE-2025-32433
nomisec WORKING POC 3 stars
by darses · poc
https://github.com/darses/CVE-2025-32433
nomisec WORKING POC 3 stars
by dollarboysushil · remote
https://github.com/dollarboysushil/CVE-2025-32433-Erlang-OTP-SSH-Unauthenticated-RCE
nomisec WORKING POC 3 stars
by exa-offsec · remote
https://github.com/exa-offsec/ssh_erlangotp_rce
nomisec SUSPICIOUS 3 stars
by LemieOne · poc
https://github.com/LemieOne/CVE-2025-32433
github WORKING POC 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-32433
nomisec WORKING POC 2 stars
by mirmeweu · remote
https://github.com/mirmeweu/cve-2025-32433
nomisec SCANNER 2 stars
by Yuri08loveElaina · remote
https://github.com/Yuri08loveElaina/CVE-2025-32433-Erlang-OTP-SSH-Pre-Auth-RCE-exploit
nomisec NO CODE 1 stars
by becrevex · infoleak
https://github.com/becrevex/CVE-2025-32433
github WORKING POC 1 stars
by toshithh · pythonremote
https://github.com/toshithh/CVE-2025-32433
nomisec WORKING POC 1 stars
by AntonieSoga · poc
https://github.com/AntonieSoga/Erlang-OTP-PoC_CVE-2025-32433
nomisec WORKING POC 1 stars
by bilalz5-github · poc
https://github.com/bilalz5-github/Erlang-OTP-SSH-CVE-2025-32433
nomisec STUB 1 stars
by Know56 · poc
https://github.com/Know56/CVE-2025-32433
nomisec WORKING POC 1 stars
by iteride · remote
https://github.com/iteride/CVE-2025-32433
nomisec WORKING POC 1 stars
by teamtopkarl · remote
https://github.com/teamtopkarl/CVE-2025-32433
nomisec WORKING POC 1 stars
by joshuavanderpoll · poc
https://github.com/joshuavanderpoll/cve-2025-32433
nomisec WORKING POC 1 stars
by yonathanpy · remote
https://github.com/yonathanpy/CVE-2025-32433.py
github WORKING POC
by accuknox · pythonpoc
https://github.com/accuknox/CVE-PoC-Collection/tree/main/CVE-2025-32433
nomisec WRITEUP
by C9b3rD3vi1 · poc
https://github.com/C9b3rD3vi1/Erlang-OTP-SSH-CVE-2025-32433
nomisec SCANNER
by te0rwx · poc
https://github.com/te0rwx/CVE-2025-32433-Detection
nomisec WORKING POC
by meloppeitreet · remote
https://github.com/meloppeitreet/CVE-2025-32433-Remote-Shell
nomisec WORKING POC
by ps-interactive · remote
https://github.com/ps-interactive/lab_CVE-2025-32433
nomisec WORKING POC
by MrDreamReal · remote
https://github.com/MrDreamReal/CVE-2025-32433
nomisec WORKING POC
by abrewer251 · remote
https://github.com/abrewer251/CVE-2025-32433_Erlang-OTP_PoC
nomisec WORKING POC
by ODST-Forge · remote
https://github.com/ODST-Forge/CVE-2025-32433_PoC
nomisec WRITEUP
by vigilante-1337 · remote
https://github.com/vigilante-1337/CVE-2025-32433
nomisec WORKING POC
by Mdusmandasthaheer · remote
https://github.com/Mdusmandasthaheer/CVE-2025-32433
nomisec WORKING POC
by l1nuxkid · remote
https://github.com/l1nuxkid/CVE-2025-32433-exploit
nomisec WORKING POC
by soltanali0 · remote
https://github.com/soltanali0/CVE-2025-32433-Eploit
nomisec WORKING POC
by giriaryan694-a11y · remote
https://github.com/giriaryan694-a11y/cve-2025-32433_rce_exploit
nomisec WORKING POC
by blackcat4347 · remote
https://github.com/blackcat4347/CVE-2025-32433-available-for-windows
nomisec WORKING POC
by carlosalbertotuma · remote
https://github.com/carlosalbertotuma/CVE-2025-32433
github WORKING POC
by Batman529 · pythonremote
https://github.com/Batman529/PoC-CVE-2025-32433
nomisec WORKING POC
by agustfricke · poc
https://github.com/agustfricke/erlang-ssh-rce-CVE-2025-32433
metasploit WORKING POC EXCELLENT
by Horizon3 Attack Team, Matt Keeley, Martin Kristiansen, mekhalleh (RAMELLA Sebastien) · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/ssh/ssh_erlangotp_rce.rb
vulncheck_xdb WORKING POC
remote
https://github.com/platsecurity/CVE-2025-32433

Nuclei Templates (1)

Erlang/OTP SSH - Remote Code Execution
CRITICALVERIFIEDby iamnoooob,rootxharsh,pdresearch,darses
Shodan: Erlang OTP

Scores

CVSS v3 10.0
EPSS 0.5031
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2025-06-09
VulnCheck KEV 2025-06-09
ENISA EUVD EUVD-2025-11793

Classification

CWE
CWE-306
Status published

Affected Products (23)

erlang/erlang\/otp < 25.3.2.20
cisco/confd_basic < 7.7.19.1
cisco/network_services_orchestrator < 5.7.19.1
cisco/cloud_native_broadband_network_gateway < 2025.03.1
cisco/inode_manager
cisco/smart_phy < 25.2
cisco/ultra_packet_core < 2025.03
cisco/ultra_services_platform
cisco/staros < 2025.03
cisco/optical_site_manager < 25.2.1
cisco/ncs_2000_shelf_virtualization_orchestrator_firmware < 25.1.1
cisco/enterprise_nfv_infrastructure_software < 4.18
cisco/ultra_cloud_core < 2025.03.1
cisco/rv160w_firmware
cisco/rv260_firmware
... and 8 more

Timeline

Published Apr 16, 2025
KEV Added Jun 09, 2025
Tracked Since Feb 18, 2026