Defending against the CVE-2025-55182 (React2Shell) vulnerability in React Server Components
Essential information
- Published
- 15/12/2025 21:41
- Modified
- 21/12/2025 19:05
- Tags
- 2025-12-15 CVE-2025-55182 etherrat react2shell remote code execution snowlight vshell vulnerability
- Related entities
- 6 vulnerabilities (cve), 50 observables, 19 techniques (mitre), 6 malware, 9 others
Description
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Vulnerabilities (CVE) (6)
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- Published
- 03/11/2021
- Modified
- 20/12/2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, …
- Attack vector
- Network
- Published
- 05/12/2025
- Modified
- 29/05/2026
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- Published
- 03/11/2021
- Modified
- 21/12/2025
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- Published
- 03/11/2021
- Modified
- 20/12/2025
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- Published
- 03/11/2021
- Modified
- 21/12/2025
Rejected reason: This CVE is a duplicate of CVE-2025-55182.
- Published
- 20/12/2025
- Modified
- 21/12/2025
Observables (50)
46.36.37.8592.246.87.48194.69.203.32http://194.69.203.32:81/hiddenbink/colonna.archttp://194.69.203.32:81/hiddenbink/react.shhttps://overcome-pmc-conferencing-books.trycloudflare.com/p.pnghttp://krebsec.anondns.net:2316/donghttp://xpertclient.net:3000/sex.shhttp://donaldjtrmp.anondns.net:1488/labubuhttp://anywherehost.site/xms/kill2.shhttps://ghostbin.axel.org/paste/evwgo/rawhttp://196.251.100.191/no_killer/Exodus.x86http://194.69.203.32:81/hiddenbink/colonna.i686http://superminecraft.net.br:3000/sex.shhttp://196.251.100.191/no_killer/Exodus.arm4http://196.251.100.191/no_killer/Exodus.x86_64http://labubu.anondns.net:1488/donghttp://anywherehost.site/xms/k1.sh69f2789a539fc2867570f3bbb71102373a94c7153239599478af84b9c81f2a03f0d3d5668a4df347eb0a59df167acddb245f022a518a6d15e37614af0bbc2adf0aad73947fb1876923709213333099b8c728dde9f5d86acfd0f3702a963bae6a7909046e5e0fd60461b721c0ef7cfe5899f76672e4970d629bb51bb904a05398b33d468641a0d3c897e571426804c65daae3ed939eab4126c3aa3fa8531de5e859630d8f3b4db5acbcaccc0cfa54500f2bbb0745d4b5c50d903636f120fc8700717c849a1331b63860cefa128a4aa5d476f300ac45fd5d3c56b2746f7e72a0d2c2867570f3bbb71102373a94c7153239599478af84b9c81f2a0368de36f14a7cd71779df5e4126c389e7702f975049bd17cb597ebcf03c6b110b59630d8f3b4d7e0a0c48ee0f65c72a252335f6dcd435dbd448fc0414b295f635372e1c5a9171c6c7e7dd85c0578dd7cb24b012a665a9d5210cce8ff735635a45605c3af1f6ad244bf271d2e55cd737980322de37c2c2792154b4cf4e4893e9908c2819026e5f9dde35ba8e132ebed29e70f57da0c4f36a9401a7bbd36e6ddd257e0920aa40839e9514533a347d7c6bc830369c7528e07af5c93e0bf7c1cd86df717c849a133182335954bec84cbdd019cfa474f20f4274310a1477e03e34af7c62d15096fe0df347eb0a59df167acddb245f022a518a6d15e37614af0bbc2adf317e10c4068b661d3721adaa35a30728739defddbc72b841c3d06aca0abd4d5e0aad73947fb1d60461b721c0ef7cfe5899f76672e4970d629bb51bb904a053987e0a0c48ee0f317e10c4068b661d3721adaa35a30728739defddbc72b841c3d06aca0abd4d5ef0b66629fe8ad71779df5e4126c389e7702f975049bd17cb597ebcf03c6b110b4cbdd019cfa474f20f4274310a1477e03e34af7c62d15096fe0df0d3d5668a4d68de36f14a7c9e9514533a347d7c6bc830369c7528e07af5c93e0bf7c1cd86dfb5acbcaccc0cfa54500f2bbb0745d4b5c50d903636f120fc870082335954bec8b568582240509227ff7e79b6dc73c933dcc3fae674e9244441066928b1ea0560f1ee866f6f03ff815009ff8fd7b70b902bc59b037ac54b6cae9b8e07beb854f7876923709213333099b8c728dde9f5d86acfd0f3702a963bae6a9dde35ba8e137e90c174829bd4e01e86779d596710ad161dbc0e02a219d6227f244bf271d2e5d3c897e571426804c65daae3ed939eab4126c3aa3fa8531de5e8f0b66629fe8a240afa3a6457f1ee866f6f03ff815009ff8fd7b70b902bc59b037ac54b6cae9b8e07beb854f77e90c174829bd4e01e86779d596710ad161dbc0e02a219d6227f2ebed29e70f57da0c4f36a9401a7bbd36e6ddd257e0920aa4083240afa3a6457b63860cefa128a4aa5d476f300ac45fd5d3c56b2746f7e72a0d27909046e5e0f
Techniques (MITRE) (19)
-
Valid Accounts
-
Permission Groups Discovery
-
Process Injection
-
Scheduled Task/Job
-
Impair Defenses
-
System Network Configuration Discovery
-
Web Shell
-
Obfuscated Files or Information
-
Exploit Public-Facing Application
-
Ingress Tool Transfer
-
Command and Scripting Interpreter
-
Steal Web Session Cookie
-
Account Discovery
-
System Owner/User Discovery
-
Remote Services
-
Unsecured Credentials
-
System Binary Proxy Execution
-
T1580
-
System Information Discovery
Malware (6)
-
FamilyPublished 05/05/2026 14:07 · Modified 05/05/2026 14:07
-
FamilyPublished 30/04/2026 19:11 · Modified 30/04/2026 19:11
-
FamilyPublished 30/04/2026 19:11 · Modified 30/04/2026 19:11
-
FamilyPublished 16/06/2026 14:27 · Modified 16/06/2026 14:27
-
FamilyPublished 05/05/2026 14:07 · Modified 05/05/2026 14:07
-
FamilyPublished 28/05/2026 10:56 · Modified 28/05/2026 10:56
Others (9)
- superminecraft.net.br
- anywherehost.site
- labubu.anondns.net
- overcome-pmc-conferencing-books.trycloudflare.com
- xpertclient.net
- ghostbin.axel.org
- vps-zap812595-1.zap-srv.com
- donaldjtrmp.anondns.net
- krebsec.anondns.net