Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-32433 PoC — Erlang/OTP SSH Vulnerable to Pre-Authentication RCE

Source
Associated Vulnerability
Title: Erlang/OTP SSH Vulnerable to Pre-Authentication RCE (CVE-2025-32433)
Description:Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
Description
CVE-2025-32433 – Erlang/OTP SSH vulnerability allowing pre-auth RCE
Readme
## ✅ Result

The server responded to an **SSH message ID 80 (0x50)** — which is reserved for post-auth. This proves the server accepts invalid messages during the pre-auth phase, indicating **vulnerable behavior as defined in CVE-2025-32433**.

<img width="959" alt="Python code is executed" src="https://github.com/user-attachments/assets/b5253b1a-ca28-486f-9433-580a157739a1" />

---

## 📖 Research Summary

I built this lab after studying Erlang/OTP and the CVE from various trusted sources.

**Erlang/OTP** is a powerful environment originally developed by Ericsson to build scalable and fault-tolerant distributed systems. It includes its own **SSH server implementation**. The SSH module inside Erlang/OTP is vulnerable to **unauthenticated remote code execution (RCE)** due to incorrect handling of **SSH message types ≥ 80 during the pre-auth phase**.

Instead of rejecting these invalid messages, the server processes them — which allows an attacker to craft malicious messages and potentially gain unauthorized code execution access.

---

### 🔍 Key Things I Learned

- **Erlang/OTP SSH** allows secure shell/file access within Erlang systems  
- **Message ID 80+** is reserved for post-authentication but can be abused pre-auth  
- **Detection**: Suricata or NIDS can spot “SSH_MSG_CHANNEL_REQUEST” with “exec” commands  
- **Affected Versions**:
  - OTP-27.3.2 and below
  - OTP-26.2.5.10 and below
  - OTP-25.3.2.19 and below  
- **Patched Versions**:
  - OTP-27.3.3
  - OTP-26.2.5.11
  - OTP-25.3.2.20

---

### 📚 Credits & Reference

- [GitHub Security Advisory – GHSA-37cp-fgq5-7wc2](https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2)  
- Research PoC and writeups by [Matthew Keeley](https://github.com/ProDefense/CVE-2025-32433)  
- Community detection insights via Suricata, Wireshark, and FortiGate  
- Official Erlang/OTP documentation and CVE pages

---



### 💬 Final Note  
*Not all content here is 100% original — I built the lab & PoC myself but studied from multiple sources to understand Erlang, OTP, SSH, and CVE-2025-32433 clearly. This README reflects my own summary and learning.* 🤝
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →