Erlang/OTP SSH Flaw Lets Hackers Bypass Login and Run Code

Red | Vulnerability Report
Download PDF

CVE-2025-32433 is a critical unauthenticated remote code execution vulnerability in the Erlang/OTP SSH server, rated CVSS 10.0 for its maximum severity. It allows attackers to execute arbitrary commands without valid credentials by exploiting improper handling of SSH messages before authentication. Affected systems are highly exposed to takeover. Users should patch immediately or restrict SSH access to mitigate risk.