logo

China-Nexus Hackers Actively Exploiting React2Shell Vulnerability (CVE-2025-55182) in the Wild

ID: 145fe315-48b0-5ab5-9418-f399c6a37aeb

STIX ID: report--145fe315-48b0-5ab5-9418-f399c6a37aeb

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-05

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

React2Shell (CVE-2025-55182) is a critical (CVSS 10.0) unauthenticated RCE in React Server Components / Next.js App Router that allows unsafe deserialization of crafted POST requests to execute code on Node.js servers; AWS observed active exploitation and probing by China-nexus groups, and the report provides example payloads, HTTP indicators (e.g. next-action, rsc-action-id, $"@), and recommends immediate patching and defensive WAF/hunting measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.