CVE-2025-32433: Unauthenticated Remote Code Execution in Erlang/OTP SSH
Posted by Fabian Bäumer on Apr 16 Hi all,
we (Fabian Bäumer, Marcus Brinkmann, Marcel Maehren, Jörg Schwenk (Ruhr
University Bochum)) found a critical security vulnerability in the
Erlang/OTP SSH implementation. The vulnerability allows an attacker with
network access to an Erlang/OTP SSH server to execute arbitrary code
without prior authentication. This vulnerability has been assigned
CVE-2025-32433 with an estimated CVSSv3 of 10.0...