Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability

Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE.

Published 13 Aug 2026Updated 13 Aug 202641 sources
CVSS 0.0 PoC CANDIDATE△ CISA KEV

What happened

Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE.

Affected versions

Erlang/OTP: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
PoC-in-GitHub · ProDefense/CVE-2025-32433CVE-2025-32433 https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2★ 143ProDefense2025-04-18CandidatePoC-in-GitHub · ekomsSavior/POC_CVE-2025-32433★ 5ekomsSavior2025-04-18CandidatePoC-in-GitHub · darses/CVE-2025-32433Security research on Erlang/OTP SSH CVE-2025-32433.★ 3darses2025-04-18CandidatePoC-in-GitHub · LemieOne/CVE-2025-32433Missing Authentication for Critical Function (CWE-306)-Exploit★ 3LemieOne2025-04-18CandidatePoC-in-GitHub · teamtopkarl/CVE-2025-32433Erlang/OTP SSH 远程代码执行漏洞★ 1teamtopkarl2025-04-18CandidatePoC-in-GitHub · m0usem0use/erl_mousepython script to find vulnerable targets of CVE-2025-32433★ 5m0usem0use2025-04-18CandidatePoC-in-GitHub · exa-offsec/ssh_erlangotp_rceExploitation module for CVE-2025-32433 (Erlang/OTP)★ 3exa-offsec2025-04-18CandidatePoC-in-GitHub · omer-efe-curkus/CVE-2025-32433-Erlang-OTP-SSH-RCE-PoCThe vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.★ 16omer-efe-curkus2025-04-18CandidatePoC-in-GitHub · 0xPThree/cve-2025-32433★ 60xPThree2025-04-19CandidatePoC-in-GitHub · meloppeitreet/CVE-2025-32433-Remote-ShellGo-based exploit for CVE-2025-32433★ 0meloppeitreet2025-04-19CandidatePoC-in-GitHub · ps-interactive/lab_CVE-2025-32433CVE lab to accompany CVE course for CVE-2025-32433★ 0ps-interactive2025-04-24CandidatePoC-in-GitHub · 0x7556/CVE-2025-32433CVE-2025-32433 Erlang/OTP SSH RCE Exploit SSH远程代码执行漏洞EXP★ 30x75562025-04-25CandidatePoC-in-GitHub · becrevex/CVE-2025-32433Erlang OTP SSH NSE Discovery Script★ 1becrevex2025-04-25CandidatePoC-in-GitHub · MrDreamReal/CVE-2025-32433CVE-2025-32433 Summary and Attack Overview★ 0MrDreamReal2025-04-27CandidatePoC-in-GitHub · Know56/CVE-2025-32433CVE-2025-32433 is a vuln of ssh★ 1Know562025-04-28CandidatePoC-in-GitHub · abrewer251/CVE-2025-32433_Erlang-OTP_PoCThis script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems running Erlang-based SSH servers★ 1abrewer2512025-04-29CandidatePoC-in-GitHub · ODST-Forge/CVE-2025-32433_PoCThis script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems running Erlang-based SSH servers★ 0ODST-Forge2025-04-29CandidatePoC-in-GitHub · bilalz5-github/Erlang-OTP-SSH-CVE-2025-32433CVE-2025-32433 – Erlang/OTP SSH vulnerability allowing pre-auth RCE★ 1bilalz5-github2025-05-02CandidatePoC-in-GitHub · vigilante-1337/CVE-2025-32433A critical flaw has been discovered in Erlang/OTP's SSH server allows unauthenticated attackers to gain remote code execution. One malformed SSH handshake bypasses authentication and exploits improper handling of SSH protocol messages.★ 0vigilante-13372025-05-03CandidatePoC-in-GitHub · NiteeshPujari/CVE-2025-32433-PoCCVE-2025-32433 PoC: Unauthenticated Remote Code Execution (RCE) in Erlang/OTP SSH. A proof-of-concept exploit for CVE-2025-32433★ 7NiteeshPujari2025-08-13CandidatePoC-in-GitHub · te0rwx/CVE-2025-32433-Detection★ 0te0rwx2025-08-27CandidatePoC-in-GitHub · Mdusmandasthaheer/CVE-2025-32433★ 0Mdusmandasthaheer2025-08-28CandidatePoC-in-GitHub · dollarboysushil/CVE-2025-32433-Erlang-OTP-SSH-Unauthenticated-RCEPoC showing unauthenticated remote code execution in Erlang/OTP SSH server. By exploiting a flaw in SSH protocol message handling, an attacker can execute arbitrary commands on the target without valid credentials.★ 3dollarboysushil2025-09-07CandidatePoC-in-GitHub · iteride/CVE-2025-32433test★ 1iteride2025-09-18CandidatePoC-in-GitHub · mirmeweu/cve-2025-32433the task from C*****k★ 2mirmeweu2025-09-24CandidatePoC-in-GitHub · Batman529/PoC-CVE-2025-32433These is a PoC for the CVE-2025-32433 vulnerability, do NOT test on systems that you dont own!!!★ 0Batman5292025-10-19CandidatePoC-in-GitHub · toshithh/CVE-2025-32433★ 2toshithh2025-10-20CandidatePoC-in-GitHub · l1nuxkid/CVE-2025-32433-exploit★ 0l1nuxkid2025-11-08CandidatePoC-in-GitHub · soltanali0/CVE-2025-32433-EploitErlang/OTP SSH Vulnerable to Pre-Authentication RCE★ 0soltanali02025-11-27CandidatePoC-in-GitHub · AntonieSoga/Erlang-OTP-PoC_CVE-2025-32433★ 2AntonieSoga2025-12-29CandidatePoC-in-GitHub · blackcat4347/CVE-2025-32433-available-for-windowsCVE-2025-32433-available-for-windows-victims★ 0blackcat43472026-02-02CandidatePoC-in-GitHub · carlosalbertotuma/CVE-2025-32433★ 0carlosalbertotuma2026-02-24CandidatePoC-in-GitHub · yonathanpy/CVE-2025-32433.pyCVE-2025-32433 PoC – SSH Protocol Python-based PoC for controlled lab testing of SSH message handling, channel operations, and pre-auth interactions. Designed for safe security research and analysis.★ 3yonathanpy2026-02-26CandidatePoC-in-GitHub · joshuavanderpoll/cve-2025-32433Go PoC for CVE-2025-32433 — unauthenticated RCE in Erlang/OTP SSH.★ 3joshuavanderpoll2026-03-07CandidatePoC-in-GitHub · 0xBlackash/CVE-2025-32433CVE-2025-32433★ 00xBlackash2026-04-09CandidatePoC-in-GitHub · chuzouX/CVE-2025-32433-Exploit-editedBased on the original version:https://github.com/vulhub/vulhub/blob/master/erlang/CVE-2025-32433/exploit.py Replace Unicode checkmark with ASCII character for Windows compatibility★ 0chuzouX2026-06-08CandidatePoC-in-GitHub · dampedcoast/Exploiting-a-vulnerability-using-reverse-shellThis project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE vulnerability (CVE-2025-32433) in an Erlang/OTP SSH server, crack extracted password hashes, and then harden the victim machine with firewall rules and patching.★ 0dampedcoast2026-06-12CandidatePoC-in-GitHub · razureink/cve-2025-32433-erlang_ssh_rce_reproductionReproduction of cve-2025-32433-erlang_ssh_rce_reproduction★ 0razureink2026-07-24CandidatePoC-in-GitHub · Liam-Worsley/CVE-2025-32433-PoC-AnalysisThis is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the code does and instructions for setting up the server to perform the exploit yourself.★ 0Liam-Worsley2026-08-14Candidate