Cisco has issued a high-severity advisory (cisco-sa-erlang-otp-ssh-xyZZy) warning of a critical remote code execution (RCE) vulnerability in products using Erlang/OTP’s SSH server.
The flaw, tracked as CVE-2025-32433, allows unauthenticated attackers to execute arbitrary code on vulnerable devices, posing systemic risks to enterprise networks, cloud infrastructure, and telecom systems.
The flaw stems from improper handling of SSH messages during authentication, enabling attackers to bypass security checks and gain full control over affected systems.
With a CVSS score of 10.0, the vulnerability impacts Cisco’s Wide Area Application Services (WAAS), Network Services Orchestrator (NSO), Catalyst Center (formerly DNA Center), and multiple routing platforms.
Erlang/OTP, a framework widely used in telecom and IoT systems, confirmed the issue on April 16, 2025.
Cisco’s investigation revealed that unpatched devices could be exploited to deploy ransomware, exfiltrate data, or disrupt critical operations.
Affected Cisco Products
Cisco has categorized impacted systems into two groups:
Confirmed Vulnerable
Product Category | Cisco Product | Cisco Bug ID | Fixed Release Available |
Network Application, Service, and Acceleration | ConfD, ConfD Basic | CSCwo83759 | May 2025 |
Network Management and Provisioning | Network Services Orchestrator (NSO) | CSCwo83796 | May 2025 |
Smart PHY | CSCwo83751 | Not yet determined | |
Routing and Switching – Enterprise and Service Provider | Intelligent Node Manager | CSCwo83755 | Not yet determined |
Ultra Cloud Core – Subscriber Microservices Infrastructure | CSCwo83747 | Not yet determined |
Notably, some products (e.g., Smart PHY) accept unauthenticated SSH channel requests but are immune to RCE due to configuration safeguards.
Cisco has labeled its advisory “Interim” as it continues assessing the scope. No workarounds exist, and the company urges administrators to:
“This is a worst-case scenario—an internet-facing vulnerability with no authentication required,” said Priya Sharma, a cybersecurity analyst at SafeNet Technologies. “Organizations must assume targeted exploitation is imminent.”
The Erlang/OTP flaw highlights risks in legacy frameworks powering critical infrastructure. Telecom providers, cloud operators, and IoT manufacturers relying on Erlang are advised to conduct urgent audits.
Cisco’s disclosure follows heightened scrutiny of supply-chain vulnerabilities after recent exploits in open-source tools.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is expected to add CVE-2025-32433 to its Known Exploited Vulnerabilities Catalog.
Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!
Cybersecurity researchers are raising alarms as hackers increasingly weaponize email input fields to execute cross-site scripting…
A recent investigation by cybersecurity firm EclecticIQ, in collaboration with threat hunters, has exposed a…
Cybersecurity researchers have uncovered a dangerous new exploitation technique, dubbed the "SonicBoom Attack Chain," which…
A researcher has unveiled a novel integration between AI-powered Copilot and Microsoft's WinDbg, dramatically simplifying…
A high-severity vulnerability (CVE-2025-46762) has been discovered in Apache Parquet Java, exposing systems using the…
National Cyber Security Centre (NCSC) has issued technical guidance following a series of cyber attacks…