← volver
CVE-2025-32433

Erlang/OTP SSH Vulnerable to Pre-Authentication RCE

CVSS 10 CRITICALEPSS 97.7%● KEVCWE-306
En resumen

El servidor SSH de Erlang/OTP tiene un defecto crítico que permite que atacantes ejecuten comandos en sistemas afectados sin necesidad de contraseña o credenciales válidas. Este es un riesgo de seguridad grave porque cualquier persona en la red puede potencialmente tomar control del servidor.

Detalle técnico

Un defecto en el manejo de mensajes del protocolo SSH en versiones de Erlang/OTP anteriores a OTP-27.3.3, OTP-26.2.5.11 y OTP-25.3.2.20 permite ejecución remota de código no autenticada. La vulnerabilidad requiere acceso de red al servidor SSH pero ninguna autenticación previa; los atacantes pueden explotar validación inadecuada de mensajes para ejecutar comandos arbitrarios con privilegios del servidor.

Resumen generado y traducido por IA a partir de la descripción oficial.
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Productos afectados
erlang · otp
PoCs públicas encontradas39
githubgithub.com/ProDefense/CVE-2025-32433142githubgithub.com/omer-efe-curkus/CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC16githubgithub.com/NiteeshPujari/CVE-2025-32433-PoC7githubgithub.com/0xPThree/cve-2025-324336githubgithub.com/m0usem0use/erl_mouse5githubgithub.com/ekomsSavior/POC_CVE-2025-324335githubgithub.com/exa-offsec/ssh_erlangotp_rce3githubgithub.com/dollarboysushil/CVE-2025-32433-Erlang-OTP-SSH-Unauthenticated-RCE3githubgithub.com/LemieOne/CVE-2025-324333githubgithub.com/0x7556/CVE-2025-324333githubgithub.com/darses/CVE-2025-324333githubgithub.com/yonathanpy/CVE-2025-32433.py2githubgithub.com/mirmeweu/cve-2025-324332githubgithub.com/AntonieSoga/Erlang-OTP-PoC_CVE-2025-324332githubgithub.com/joshuavanderpoll/cve-2025-324332githubgithub.com/becrevex/CVE-2025-324331githubgithub.com/Know56/CVE-2025-324331githubgithub.com/teamtopkarl/CVE-2025-324331githubgithub.com/bilalz5-github/Erlang-OTP-SSH-CVE-2025-324331githubgithub.com/iteride/CVE-2025-324331githubgithub.com/vigilante-1337/CVE-2025-324330githubgithub.com/Epivalent/CVE-2025-32433-detection0githubgithub.com/meloppeitreet/CVE-2025-32433-Remote-Shell0githubgithub.com/ps-interactive/lab_CVE-2025-324330githubgithub.com/MrDreamReal/CVE-2025-324330githubgithub.com/abrewer251/CVE-2025-32433_Erlang-OTP_PoC0githubgithub.com/te0rwx/CVE-2025-32433-Detection0githubgithub.com/Mdusmandasthaheer/CVE-2025-324330githubgithub.com/l1nuxkid/CVE-2025-32433-exploit0githubgithub.com/soltanali0/CVE-2025-32433-Eploit0githubgithub.com/giriaryan694-a11y/cve-2025-32433_rce_exploit0githubgithub.com/blackcat4347/CVE-2025-32433-available-for-windows0githubgithub.com/carlosalbertotuma/CVE-2025-324330githubgithub.com/0xBlackash/CVE-2025-324330githubgithub.com/leehunkoo/hk_CVE-2025-324330githubgithub.com/chuzouX/CVE-2025-32433-Exploit-edited0githubgithub.com/dampedcoast/Exploiting-a-vulnerability-using-reverse-shell0githubgithub.com/ODST-Forge/CVE-2025-32433_PoC0cve_referencegithub.com/ProDefense/CVE-2025-32433/blob/main/CVE-2025-32433.pyno verificado
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →