
Missing Authentication for Critical Function (CWE-306)-Exploit
A critical vulnerability in Erlang/OTP SSH server allows unauthenticated remote code execution (RCE). The flaw exists in the SSH protocol message handling mechanism, enabling attackers to execute arbitrary commands without requiring authentication credentials.
Critical severity vulnerability that enables attackers to potentially: - Escape the browser's sandbox protection - Execute arbitrary code - Compromise system integrity - Gain unauthorized access to system resources This vulnerability specifically targets Firefox on Windows and was being actively exploited in the wild. If SSH daemon is running as root, the attacker has full access to that device
CVE ID: CVE-2025-32433
Published: 04/16/2025
Impact: Critical
Exploit Availability: Not public, only private.
CVSS: 10
Patch Available: (No official patch yet)
Erlang/OTP SSH