CVE-2025-32433General(cisco / cloud_native_broadband_network_gateway)

CRITICALCVSS 10.0 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch cisco cloud_native_broadband_network_gateway systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-06-30. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-306

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_native_broadband_network_gateway
  • confd_basic
  • debian_linux
  • enterprise_nfv_infrastructure_software

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 23 mentions across 15 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • General: 6 classified signals
  • Disclosure: 3 classified signals
  • Peaked 11d ago at 3 mentions (2026-02-15); latest day: 3
  • 23 total mentions across 15 days

Affected systems

Products
cloud_native_broadband_network_gatewayconfd_basicdebian_linuxenterprise_nfv_infrastructure_softwareerlang\/otpinode_managerncs_1001ncs_1002ncs_1004ncs_2000_shelf_virtualization_orchestrator_firmware

2 versions affected across 36 products

Deep dive

Activity timeline23 mentions / 15d
01223Mentions · 2026-02-08: 1Mentions · 2026-02-12: 1Mentions · 2026-02-14: 1Mentions · 2026-02-15: 3Mentions · 2026-02-16: 1Mentions · 2026-03-07: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Mentions · 2026-05-08: 1Mentions · 2026-06-22: 1Mentions · 2026-07-12: 1Mentions · 2026-08-17: 2Mentions · 2026-09-19: 2Mentions · 2026-09-28: 3Mentions · 2026-09-29: 3PoC Mentioned / Linked · 2026-02-08: 1PoC Mentioned / Linked · 2026-02-15: 1PoC Mentioned / Linked · 2026-02-16: 1PoC Mentioned / Linked · 2026-03-07: 1PoC Mentioned / Linked · 2026-07-12: 1PoC Mentioned / Linked · 2026-08-17: 1PoC Mentioned / Linked · 2026-09-19: 1Exploit Tool / Code · 2026-02-16: 1Exploit Tool / Code · 2026-08-17: 1Active Exploitation · 2026-06-22: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-15: 3Technical Details · 2026-03-15: 1Technical Details · 2026-06-22: 1Technical Details · 2026-07-12: 102-0802-1202-1402-1502-1603-0703-1403-1505-0806-2207-1208-1709-1909-2809-29
Signal classification5 categories
General
635.3%
PoC
529.4%
Disclosure
317.6%
Exploit
211.8%
Patch
15.9%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-081
PoC1
2026-02-121
General1
2026-02-141
PoC1
2026-02-153
Disclosure1General1PoC1
2026-02-161
Exploit1
2026-03-071
PoC1
2026-03-141
General1
2026-03-151
Disclosure1
2026-05-081
General1
2026-06-221
Patch1
2026-07-121
Disclosure1
2026-08-172
Exploit1General1
2026-09-192
General1PoC1
Full discourse20 posts
  • Swissky@pentest_swissky
    Exploit

    How I Used AI to Create a Working Exploit for CVE-2025-32433 Before Public PoCs Existed - Matthew Keeley https://platformsecurity.com/blog/CVE-2025-32433-poc

    Post summary

    The article announces that the author used AI to create and share a functional exploit for CVE‑2025‑32433 before any public PoCs were available.

    0120112797.4K
    21.0K followersView on X
  • Nightbane / Matt Keeley@Nightbanes
    PoC

    @dez_ @_RastaMouse It’s been great, even with the older models! https://platformsecurity.com/blog/CVE-2025-32433-poc I think OSS software will be hit the hardest, making supply chain security one of the biggest threats of 2026

    Post summary

    The tweet announces a PoC for CVE‑2025‑32433 via a linked blog, with no evidence of exploitation, patches, or technical specifics in the text.

    00056534
    2.6K followersView on X
  • ExploitGrid@exploitgrid

    #ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2021-44228 (CVSS: 10) #Apache Softw... CVE-2021-44228 (CVSS: 10) Apache Softw... CVE-2025-32433 (CVSS: 10) erlang CVE-2026-100382 (CVSS: 10) Wikimedia Fo... CVE-2026-97163 (CVSS: 10) https://lomart.fr ..🧵👇

    10032570
    374 followersView on X
  • Tracert_Dev@TracertDev
    General

    CVE-2025-32433

    Post summary

    The text only references the CVE identifier CVE‑2025‑32433 without providing any additional information about disclosure, exploitation, or remediation.

    00040191
    327 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2021-44228 CVE-2025-24813 CVE-2025-32433 CVE-2026-32604 CVE-2024-30804 ..🧵👇

    Post summary

    The post serves as a daily threat digest header listing five CVE identifiers (including future-dated ones) without providing technical details, exploitation status, patches, or proof-of-concept references.

    1101088
    50 followersView on X
  • John McGinnis@JohnMcGinn90325
    General

    @CyberRacheal For those that say port 22, you might want to review CVE-2025-32433, CVE-2024-6387, CVE-2025-61984. Need to review version and patch levels and you still might be vulnerable. Remote access should be frontended with a private VPN. Yes I am paranoid.

    Post summary

    The post reminds readers to review patch status for CVE-2025-32433, CVE-2024-6387, and CVE-2025-61984 and to use a private VPN, but does not provide a PoC, exploit code, or evidence of active exploitation.

    1002054
    319 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2021-44228 (Log4Shell) · 2 PoCs live, 4+ years old and still active ├ CVE-2025-32433 · Erlang · PoC live ├ CVE-2026-100382 · MediaWiki · PoC live └ CVE-2026-97163 · Joomla (https://lomart.fr) · PoC live +339 more tracked today.

    1000042
    365 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2025-32433 [CRITICAL/PoC] CVSS: 10 | Vendor: #erlang Reproduce-CVE-2025-32433 🔗 https://exploitgrid.net/exploits/dbeb5110-a09e-448d-925f-d3f939688a0e

    1000060
    365 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2021-44228 (Log4Shell) · 2 PoCs live, still going strong 4+ years later ├ CVE-2025-32433 · Erlang · PoC live ├ CVE-2026-100382 · MediaWiki · PoC live └ CVE-2026-97163 · Joomla (https://lomart.fr) · PoC live

    1000076
    356 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2025-32433 [CRITICAL/PoC] CVSS: 10 | Vendor: #erlang Reproduce-CVE-2025-32433 🔗 https://exploitgrid.net/exploits/dbeb5110-a09e-448d-925f-d3f939688a0e

    1000051
    356 followersView on X
  • ExploitGrid@exploitgrid

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2021-44228 CVE-2021-44228 CVE-2025-32433 CVE-2026-100382 CVE-2026-97163 ..🧵👇

    10000100
    356 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] CVE-2025-32433 [CRITICAL/PoC] CVE-2025-32433-LAB 🔗 https://exploitgrid.net/exploits/6866171d-8dd0-494b-9d0e-c63616c8c371

    Post summary

    The text explicitly references CVE-2025-32433 as [CRITICAL/PoC], indicating a Proof of Concept is associated. No functional exploit, active exploitation, or patch information is provided in the tweet text.

    1000052
    50 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-EjpQM0Q [CRITICAL/PoC] Linked: CVE-2025-3243, CVE-2025-32433 CVE-2025-3243 🔗 https://exploitgrid.net/exploits/04f5ed1c-9f92-4e95-8e28-e010f831ef99

    Post summary

    The post announces a critical PoC for CVE‑2025‑3243, providing a link to a functional exploit on ExploitGrid, but offers no evidence of active exploitation, patching, or in‑depth technical details.

    1000021
    33 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-z2Wb7PG ( CVE-2026-72898 ) EGE-GH-UkSJfvx ( CVE-2026-73678 ) EGE-GH-MKUk78n ( CVE-2023-22621 ) EGE-GH-EjpQM0Q ( CVE-2025-3243, CVE-2025-32433 ) EGE-GH-seDm3r2 ( CVE-2025-55182 ) ..🧵👇

    Post summary

    The post simply lists several CVE identifiers associated with daily exploit disclosures without additional context or details.

    1000042
    33 followersView on X
  • r0otk3r@r0otk3r
    Disclosure

    🚨 CVE-2025-32433: Critical 10.0 CVSS Erlang/OTP SSH Server Pre-Auth RCE https://www.youtube.com/watch?v=ve0cQbiamuo #Cybersecurity #Infosec #AppSec #RCE #Erlang #OTP #SSH #CVE202532433 #PoC #EthicalHacking #BugBounty #PatchNow https://t.co/NcyvlcdIuv

    Post summary

    The tweet announces a critically scored pre‑authentication RCE vulnerability in Erlang/OTP SSH, links to a video likely showing a PoC, but does not supply exploit code, patch details, or evidence of active exploitation.

    0001048
    43 followersView on X
  • Himadri Singh@LittleSun4lower
    General

    I just completed Erlang/OTP SSH: CVE-2025-32433 room on TryHackMe! Learn about and exploit Erlang/OTP SSH CVE-2025-32433 in a lab setup. https://tryhackme.com/room/erlangotpsshcve202532433?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #Learning #Consistency

    Post summary

    The poster completed a TryHackMe room for the Erlang/OTP SSH CVE‑2025‑32433, offering a lab environment to learn and exploit the vulnerability.

    000101.1K
    8 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @sckull_ CVE-2025-32433 targets Erlang/OTP (an Erlang runtime used in systems like RabbitMQ or Ejabberd), enabling RCE over SSH, likely through deserialization flaws or command injection in SSH handlers—common in OTP versions before patches. ⚠️ #Erlang #RCE

    Post summary

    The tweet announces CVE‑2025‑32433 as an RCE vulnerability in Erlang/OTP via SSH, likely caused by deserialization or command injection, but provides no PoC, exploit code, or patch details.

    1000048
    313 followersView on X
  • transilienceai@transilienceai
    General

    @sckull_ HackTheBox "Soulmate" is a cybersecurity challenge featuring an authentication bypass vulnerability in CrushFTP and a remote code execution (RCE) exploit in Erlang/OTP SSH via CVE-2025-32433. 🔍💻 #HackTheBox #Cybersecurity

    Post summary

    HackTheBox challenge highlights a CrushFTP authentication bypass and an RCE in Erlang/OTP SSH (CVE-2025-32433) but provides no PoC, exploit code, or patch information.

    1000045
    313 followersView on X
  • sckull@sckull_
    PoC

    HackTheBox - Soulmate 💥 Authentication Bypass en CrushFTP 🚀 RCE en Erlang/OTP SSH - CVE-2025-32433 https://sckull.github.io/posts/soulmate/

    Post summary

    The post announces an authentication bypass leading to RCE in CrushFTP's Erlang/OTP SSH (CVE-2025-32433) and provides a link to a PoC.

    1000053
    177 followersView on X
  • Silent Vector@gh0st_V3ctbrv
    Patch

    If your org runs FortiGate, Cisco ASA, or exposed RDP, you are a target. patch immediately 👇 → CVE-2024-55591 — FortiOS auth bypass → CVE-2025-32433 — Erlang/OTP SSH RCE → CVE-2025-33073 — actively exploited + disable unused RDP exposure + enforce MFA on VPN + monitor for AD Group Policy changes + segment your backups from the main network The Gentlemen don't pick soft targets; they pick unprepared ones. Don't be unprepared. 🎩 #CyberSecurity #Ransomware #TheGentlemen #ThreatIntel #InfoSec #BugBounty #BlueTeam #RaaS

    Post summary

    The text urges immediate patching of specific FortiOS, Erlang/OTP, and another CVE (actively exploited), highlighting the need for organisations with FortiGate, Cisco ASA or exposed RDP to address these vulnerabilities promptly.

    00000121
    9.2K followersView on X
CPE platform detail36 entries

36 of 36 entries

PartVendorProductVersionTarget SWTarget HW
Appciscocloud_native_broadband_network_gateway---
Appciscoconfd_basic---
Appciscoenterprise_nfv_infrastructure_software---
Appciscoinode_manager---
HWcisconcs_1001---
HWcisconcs_1002---
HWcisconcs_1004---
OScisconcs_2000_shelf_virtualization_orchestrator_firmware---
HWcisconcs_2000_shelf_virtualization_orchestrator_module---
Appcisconetwork_services_orchestrator---
Appciscooptical_site_manager---
HWciscorv160---
OSciscorv160_firmware---
HWciscorv160w---
OSciscorv160w_firmware---
HWciscorv260---
OSciscorv260_firmware---
HWciscorv260p---
OSciscorv260p_firmware---
HWciscorv260w---
OSciscorv260w_firmware---
HWciscorv340---
OSciscorv340_firmware---
HWciscorv340w---
OSciscorv340w_firmware---
HWciscorv345---
OSciscorv345_firmware---
HWciscorv345p---
OSciscorv345p_firmware---
Appciscosmart_phy---
OSciscostaros---
Appciscoultra_cloud_core---
Appciscoultra_packet_core---
Appciscoultra_services_platform---
OSdebiandebian_linux11.0--
Apperlangerlang\/otp---

Explore more