Researchers Spot Surge in Erlang/OTP SSH RCE Exploits, 70% Target OT Firewalls

By Published On: August 15, 2025

 

Erlang/OTP SSH RCE Exploits Surge, OT Firewalls Compromised

Recent intelligence indicates a significant escalation in exploitation attempts targeting a critical vulnerability within Erlang/Open Telecom Platform (OTP) SSH. Cybersecurity researchers have observed a marked surge in these attacks, with an alarming 70% of detected compromises impacting firewalls securing vital Operational Technology (OT) networks. This development underscores an immediate and severe threat to critical infrastructure, demanding urgent attention from security professionals.

The Critical Flaw: CVE-2025-32433 Explained

The vulnerability at the heart of these widespread attacks is identified as CVE-2025-32433. This flaw carries a CVSS score of 10.0 (Critical), signifying the highest possible severity. It is classified as a missing authentication issue, meaning an attacker can bypass standard authentication mechanisms to gain unauthorized access. Such a vulnerability, when exploited, can lead to Remote Code Execution (RCE), allowing malicious actors to execute arbitrary code on the affected system with potentially catastrophic consequences.

Exploitation of CVE-2025-32433 has been observed in the wild as early as the beginning of May 2025, highlighting a clear window between the initial activity and public disclosure, or perhaps a significant delay in patching across vulnerable systems. The nature of this flaw, enabling unfettered access, makes it an attractive target for threat actors aiming for deep network penetration and control.

The OT Security Implications: A Dire Warning

The disproportionate targeting of OT firewalls is perhaps the most concerning aspect of this surge. OT environments, which control industrial control systems (ICS), SCADA systems, and other critical infrastructure, are notoriously sensitive. A compromise of an OT firewall can serve as a beachhead for attackers to:

  • Gain direct access to industrial networks.
  • Manipulate or disrupt critical physical processes.
  • Exfiltrate sensitive operational data.
  • Deploy ransomware or wiper malware across an entire industrial environment.

The direct impact on OT networks poses a significant risk of physical damage, production halts, and severe economic repercussions. Organizations managing OT assets must prioritize the immediate remediation of this vulnerability.

Remediation Actions

Given the critical nature of CVE-2025-32433 and its active exploitation, immediate action is paramount for all organizations utilizing Erlang/OTP SSH, particularly those with OT firewalls:

  • Patch Immediately: The most crucial step is to apply the security patch provided by Erlang/OTP as soon as possible. Organizations should confirm that their Erlang/OTP SSH installations are running the patched version.
  • Isolate and Segment OT Networks: Strengthen network segmentation between IT and OT environments. Even if a firewall is compromised, robust segmentation can limit an attacker’s lateral movement into critical OT assets.
  • Monitor SSH Activity: Implement stringent logging and real-time monitoring of all SSH connections, especially those originating from external networks or destined for critical internal systems. Look for anomalous login attempts, unusual command execution, or unexpected data transfers.
  • Review Firewall Rules: Regularly audit and tighten firewall rules to ensure only absolutely necessary SSH access is permitted from trusted sources. Employ a “deny-by-default” approach.
  • Implement Multi-Factor Authentication (MFA): Where possible, extend MFA to all administrative interfaces, including SSH, even if the vulnerability is patched. This adds an extra layer of defense against compromised credentials.
  • Incident Response Planning: Ensure your organization has a well-rehearsed incident response plan specifically for OT security incidents, capable of rapidly detecting, containing, and eradicating threats.

Tools for Detection and Mitigation

Leveraging appropriate tools is vital for identifying vulnerabilities and maintaining a strong security posture. Below are examples of tool categories that can assist in combating threats like CVE-2025-32433:

Tool Name/Category Purpose Link (Example)
Vulnerability Scanners (e.g., Nessus, OpenVAS) Identify known vulnerabilities, including outdated software versions and missing patches. Tenable Nessus
Network Intrusion Detection/Prevention Systems (IDS/IPS) Detect and potentially block suspicious network traffic patterns indicative of exploitation attempts. Snort
Security Information and Event Management (SIEM) Systems Aggregate and analyze security logs from various sources to detect anomalous activity and potential breaches. Splunk
Endpoint Detection and Response (EDR)/Extended Detection and Response (XDR) Monitor endpoints (like firewalls) for malicious activity, post-exploitation behavior, and facilitate rapid response. CrowdStrike Falcon

Key Takeaways for Cybersecurity Professionals

The surge in Erlang/OTP SSH RCE exploits, particularly on OT firewalls, is a stark reminder of the evolving threat landscape. Proactive patching, rigorous network segmentation, continuous monitoring, and robust incident response capabilities are not merely best practices but critical necessities. Prioritizing the security of critical infrastructure, especially against vulnerabilities with maximum severity, is non-negotiable for safeguarding operational continuity and national security.

 

Share this article

Leave A Comment