CVE‑2025‑32433: Critical Pre-authentication RCE Vulnerability in Erlang/OTP SSH Server

ISGroup Cybersecurity

A critical vulnerability has been discovered in the Erlang/OTP SSH server component, a technology widely used in telecommunications infrastructure, distributed systems, and real-time platforms. The flaw has been assigned a CVSS score of 10, reflecting both the ease of exploitation and the severe impact it can have on affected installations.

Date2025-04-21 12:48:15
Information
  • Trending
  • Fix Available

Technical Summary

The issue lies in how the built-in Erlang/OTP SSH daemon processes certain protocol messages before completing the authentication handshake. By sending specially crafted SSH_MSG_CHANNEL_OPEN and SSH_MSG_CHANNEL_REQUEST packets immediately after establishing a TCP connection, an unauthenticated user can trigger the execution of arbitrary Erlang code on the server.

Key technical points:

  • Pre-authentication channel handling: The SSH server incorrectly accepts and processes channel-related messages before verifying user credentials.

  • Remote Code Execution: Malicious payloads can invoke any Erlang function, such as writing to the filesystem or launching shell processes.

  • Total compromise: The exploit does not require a valid user account or session state, allowing for complete system compromise, data theft, or lateral movement.

Recommendations

  1. Immediate Update
  • Erlang/OTP 27 users: update to OTP‑27.3.3
  • Erlang/OTP 26 users: update to OTP‑26.2.5.11
  • Erlang/OTP 25 users: update to OTP‑25.3.2.20
  1. Temporary Mitigation
  • Disable the Erlang SSH server component if not required.
  • Otherwise, restrict access via firewall rules to trusted IPs or VPN networks only.
  1. Strengthen Network Perimeter
  • Apply SSH access controls at the network level (e.g., host-based firewalls, security groups).
  • Monitor for unexpected pre-authentication channel packets in IDS/IPS systems.
  1. Enhance Monitoring and Auditing
  • Enable SSH logging in verbose mode to capture early channel openings and exec requests.
  • Trigger alerts on anomalous or premature SSH traffic patterns.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert