Threat Advisories:
🎧 Podcast: This Month's Threats in 10 Min! Emerging Threat Intel Audio Briefing - Listen & Defend Now →
👥 Play Count: Loading...

Erlang/OTP SSH Flaw Lets Hackers Bypass Login and Run Code

Red | Vulnerability Report
Download PDF
CVE-2025-32433 is a critical unauthenticated remote code execution vulnerability in the Erlang/OTP SSH server, rated CVSS 10.0 for its maximum severity. It allows attackers to execute arbitrary commands without valid credentials by exploiting improper handling of SSH messages before authentication. The bug is already being exploited in the wild, targeting OT networks and sectors like education, healthcare, and telecom, with proof-of-concept code publicly available. Users should patch immediately or restrict SSH access to mitigate risk.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox