FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Erlang -- Erlang/OTP SSH Vulnerable to Pre-Authentication RCE

Affected packages
erlang < 26.2.5.11
erlang-runtime21 < 25.3.2.20
erlang-runtime22 < 25.3.2.20
erlang-runtime23 < 25.3.2.20
erlang-runtime24 < 25.3.2.20
erlang-runtime25 < 25.3.2.20
erlang-runtime26 < 26.2.5.11
erlang-runtime27 < 27.3.3

Details

VuXML ID 06269ae8-1e0d-11f0-ad0b-b42e991fc52e
Discovery 2025-04-16
Entry 2025-04-20

security-advisories@github.com reports:

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

References

CVE Name CVE-2025-32433
URL https://nvd.nist.gov/vuln/detail/CVE-2025-32433