React2Shell flaw (CVE-2025-55182) exploited for remote code execution
Essential information
- Published
- 12/12/2025 10:09
- Modified
- 21/12/2025 19:01
- Tags
- 2025-12-12 CVE-2025-55182 deserialization etherrat linux loaders obfuscated javascript persistence react2shell remote code execution snowlight state-sponsored attacks vshell
- Related entities
- 1 vulnerabilities (cve), 3 observables, 9 techniques (mitre), 3 malware
Description
A critical vulnerability called 'React2Shell' (CVE-2025-55182) affecting React Server Components has been widely exploited. The flaw allows remote code execution through unsafe handling of incoming data during deserialization. Over 165,000 vulnerable IP addresses have been identified. Post-exploitation activities include deploying Linux loaders, establishing persistence, installing obfuscated JavaScript, and using cloud infrastructure for command and control. Both Chinese and North Korean state-sponsored groups are suspected to be involved in the attacks. The vulnerability's exploitation is expected to expand to opportunistic cybercriminals. Organizations are advised to prioritize patching the affected React infrastructure.