China-Nexus Hackers Actively Exploiting React2Shell Vulnerability (CVE-2025-55182) in the Wild
ID: 145fe315-48b0-5ab5-9418-f399c6a37aeb
STIX ID: report--145fe315-48b0-5ab5-9418-f399c6a37aeb
Feed Name: cybersecurityNews.com
Threat Score
React2Shell (CVE-2025-55182) is a critical (CVSS 10.0) unauthenticated RCE in React Server Components / Next.js App Router that allows unsafe deserialization of crafted POST requests to execute code on Node.js servers; AWS observed active exploitation and probing by China-nexus groups, and the report provides example payloads, HTTP indicators (e.g. next-action, rsc-action-id, $"@), and recommends immediate patching and defensive WAF/hunting measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
