More React2Shell Exploits CVE-2025-55182, (Mon, Dec 15th)
ID: 493cd829-89bc-50f4-8a5b-4a4346820968
STIX ID: report--493cd829-89bc-50f4-8a5b-4a4346820968
Feed Name: SANS ISC Diary
Exploit activity targeting React2Shell (CVE-2025-55182) remains active; attackers are using multipart/form-data payloads to execute code server-side and download a binary from 51.81.104.115 into writable scratch locations like /dev/shm/lrt or /tmp, which is then made executable. The payload appears to deliver either adware or a crypto miner; recommended mitigations include patching React2Shell, hardening writable temporary directories (e.g., noexec), and monitoring the IP and file paths listed as indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
