Multiple Cisco Tools at Risk from Erlang/OTP SSH Remote Code Execution Flaw
gbhackersCisco has issued a high-severity advisory (cisco-sa-erlang-otp-ssh-xyZZy) warning of a critical remote code execution (RCE) vulnerability in products using Erlang/OTP’s SSH server.
The flaw, tracked as CVE-2025-32433, allows unauthenticated attackers to execute arbitrary code on vulnerable devices, posing systemic risks to enterprise networks, cloud infrastructure, and telecom systems.
Vulnerability Overview
The flaw stems from improper handling of SSH messages during authentication, enabling attackers to bypass security checks and gain full control over affected systems.
With a CVSS score of 10.0, the vulnerability impacts Cisco’s Wide Area Application Services (WAAS), Network Services Orchestrator (NSO), Catalyst Center (formerly DNA Center), and multiple routing platforms.
Erlang/OTP, a framework widely used in telecom and IoT systems, confirmed the issue on April 16, 2025.
Cisco’s investigation revealed that unpatched devices could be exploited to deploy ransomware, exfiltrate data, or disrupt critical operations.
Affected Cisco Products
Cisco has categorized impacted ...
Copyright of this story solely belongs to gbhackers . To see the full text click HERE