HomeSecurityReact2Shell vulnerability on CISA's KEV List - 30 organizations breached

React2Shell Vulnerability on CISA's KEV List – 30 Organizations Breached

More than 77,000 IP addresses exposed on the Internet are vulnerable to the critical React2Shell vulnerability (CVE-2025-55182), with researchers confirming that attackers have already breached over 30 organizations across multiple sectors.

React2Shell Vulnerability on CISA's KEV List - 30 Organizations Breached

React2Shell is an remote code execution unauthenticatedthat can be exploited via a single HTTP request and affects all frameworks that implement React Server Components, including Next.js, which uses the same deserialization logic. React disclosed the vulnerability on December 3, explaining that insecure client-controlled data deserialization within React Server Components allows attackers to cause remote, unauthenticated execution of arbitrary commands.

See also: Vulnerability in NVIDIA Triton allows attackers to cause DoS attack

Developers must update React to the latest version, rebuild their applications , and then redeploy them to fix the vulnerability. On December 4, security researcher Maple3142 published a proof-of-concept exploit demonstrating remote command execution on unpatched servers. Shortly thereafter, scanning for the vulnerability accelerated as attackers and researchers began using the public exploit with automated tools.

Thousands of IP addresses vulnerable

Internet monitoring group Shadowserver reports that it has identified 77,664 IP addresses vulnerable to the React2Shell vulnerability, with approximately 23,700 in the United States. Researchers determined that the IP addresses were vulnerable using a detection technique developed by Searchlight Cyber/Assetnote. An HTTP request is sent to the servers to exploit the vulnerability , and a specific response is checked to confirm whether a device is vulnerable.

GreyNoise also recorded 181 separate IP addresses attempting to exploit the vulnerability from December 5th to 6th, with most of the traffic appearing automated. Researchers say the scans are primarily coming from the Netherlands, China, the United States, Hong Kong, and a small number of other countries.

See also: Cacti vulnerability allows remote code execution

React2Shell Vulnerability on CISA's KEV List - 30 Organizations Breached

React2Shell: Over 30 organizations have already been hacked

Palo Alto Networks reports that over 30 organizations have already been compromised via the React2Shell vulnerability, with attackers exploiting the vulnerability to execute commands, conduct reconnaissance , and attempt to steal configuration and credential files. These breaches include intrusions linked to known Chinese state-sponsored threat actors.

Since its disclosure, researchers and threat intelligence firms have observed widespread exploitation of the CVE-2025-55182 vulnerability. GreyNoise reports that attackers often start with PowerShell commands that perform a basic mathematical operation to confirm that the device is vulnerable to the remote code execution vulnerability. These tests return predictable results, leaving minimal signs of exploitation.

Once remote code execution is confirmed, the attackers commands base64-encoded PowerShellthat download additional scripts directly into memory. One command executes a second-stage PowerShell script from an external website, which is used to disable AMSI, bypass endpoint security, and deploy additional payloads.

According to VirusTotal, the PowerShell script observed by GreyNoise installs a Cobalt Strike beacon on the targeted device, giving threat actors a foothold on the network.

See also: Hackers exploit command injection vulnerability in Array AG Gateways

Amazon AWS threat intelligence teams also saw a quick exploit, hours after the React vulnerability CVE-2025-55182 was disclosed. Researchers observed infrastructure associated with Chinese APT hacking groups known as Earth Lamia and Jackpot Panda . In this exploit, threat actors conduct reconnaissance on vulnerable servers using commands such as whoami and id, attempting to write files and read /etc/passwd.

React2Shell Vulnerability on CISA's KEV List - 30 Organizations Breached

Palo Alto Networks also observed similar exploitation, attributing some of these exploits to UNC5174, a Chinese state-sponsored threat actor believed to be affiliated with China's Ministry of State Security.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The malware deployed in these attacks is:

  • Snowlight: A malware dropper that allows remote attackers to send additional payloads to compromised devices.
  • Vshell: A backdoor commonly used by Chinese hacking groups for remote access, post-exploit activity, and for lateral movement across a compromised network.

CISA adds React2Shell vulnerability to KEV List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploitable Vulnerabilities (KEV) list, following reports of active exploitation online.

The vulnerability has been addressed in versions 19.0.1, 19.1.2, and 19.2.1 of the following libraries:

– react-server-dom-webpack

– react-server-dom-parcel

– react-server-dom-turbopack

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS