logo

React2Shell Under Active Exploitation by China-Nexus Hackers

ID: 6fe42824-de13-5e51-9eb1-90d6fa8f656c

STIX ID: report--6fe42824-de13-5e51-9eb1-90d6fa8f656c

Feed Name: Infosecurity Magazine (News)

Threat Score
92/100

Date Published: 2025-12-08

Date Updated: 2026-04-22

...
...

Critical pre-auth RCE (CVE-2025-55182, "React2Shell") in React Server Components is being actively exploited: AWS attributes exploitation attempts to state-linked groups Earth Lamia and Jackpot Panda, while scanners and proof-of-concept exploits (some inaccurate or malicious) have rapidly proliferated. Shadowserver and Censys report from tens of thousands to over 2.15 million potentially affected internet-facing instances, and mitigation efforts have already caused operational impact (e.g., Cloudflare failures).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.