Executive brief
Erlang/OTP is a widely used programming framework that provides the foundation for many networking products, including those from Cisco and NetApp. A critical security flaw in its SSH server component allows an attacker to bypass authentication and take full control of the system. This could lead to complete data theft, service disruption, or the installation of malware on affected infrastructure. This vulnerability is known to be actively exploited in the wild.
Technical details
A missing authentication for critical function (CWE-306) exists in the Erlang/OTP SSH server component. The vulnerability stems from a flaw in how SSH protocol messages are handled, allowing a remote, unauthenticated attacker to bypass security controls. By sending specially crafted protocol messages, an attacker can execute arbitrary commands with the privileges of the SSH service. This issue is confirmed to be exploited in the wild and affects multiple downstream vendors that integrate Erlang/OTP. Patches are available in Erlang/OTP versions 27.3.3, 26.2.5.11, and 25.3.2.20.
Affected products
- Erlang Erlang/OTP SSH Server Prior to OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20
- Cisco StarOS Prior to 2025.03
- Cisco Smart PHY Prior to 25.2
- Cisco Cloud Native Broadband Network Gateway Prior to 2025.03.1
Timeline
- 2025-06-09: disclosed
- 2025-06-09: kev added: Added to CISA KEV catalog
- 2025-06-09: advisory
- 2025-06-09: patched