logo

China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182)

ID: 25a85a59-9bc4-56aa-a45b-9c30e345882a

STIX ID: report--25a85a59-9bc4-56aa-a45b-9c30e345882a

Feed Name: AWS Security Blog

Threat Score
92/100

Date Published: 2025-12-05

Date Updated: 2026-04-27

Author: CJ Moses

...
...

Amazon observed rapid, in-the-wild exploitation attempts targeting CVE-2025-55182 (React2Shell), a critical (CVSS 10.0) unsafe deserialization RCE in React Server Components affecting React 19.x and Next.js 15.x/16.x (App Router). Multiple China state-nexus clusters (including Earth Lamia and Jackpot Panda) and other unattributed actors weaponized public PoCs within hours of disclosure; AWS detected scanning and active exploitation via MadPot, published IOCs and host/network indicators, and recommended immediate patching plus interim WAF/Network Firewall protections and logging/forensic checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.