🚨 React2Shell - CVE-2025-55182 Exploitation Framework

Advanced exploitation framework for CVE-2025-55182 (Next.js Remote Code Execution)
Author: opsecramdan
📚 Table of Contents
- Overview
- Vulnerability Details
- Features
- Requirements
- Installation
- Usage
- Interactive Shell
- Output Files
- Impact
- Mitigation
- Limitations
- Disclaimer
📌 Overview
React2Shell adalah framework exploitation untuk mengidentifikasi dan mengeksploitasi vulnerability CVE-2025-55182 pada aplikasi berbasis Next.js.
Tool ini dirancang sebagai all-in-one offensive toolkit yang mencakup:
- Subdomain enumeration
- Vulnerability scanning
- Exploitation engine
- Interactive remote shell
🔍 Vulnerability Details
- CVE ID: CVE-2025-55182
- Type: Remote Code Execution (RCE)
- Platform: Next.js
- Attack Vector: Malicious multipart/form-data request
- Impact: Arbitrary command execution
🧠 Root Cause
Vulnerability ini memanfaatkan mekanisme internal Next.js dengan cara:
- Inject payload ke request
- Memanggil: process.mainModule.require('child_process')
- Menjalankan command OS
- Encode output dalam Base64
- Leak hasil melalui redirect (
/login?a=)
⚙️ Features
🔎 Subdomain Enumeration
- DNS + HTTP scanning
- Built-in wordlist
- Custom wordlist support
- Auto save result
🧪 Vulnerability Scanner
- Multi-endpoint testing:
/
/api
/api/auth
/_next
/admin
/dashboard
- Header & response analysis
- False-positive reduction
💣 Exploitation Engine
- Automatic payload generation
- Base64 encoded execution
- Redirect-based output extraction
🖥️ Interactive Shell
- Remote command execution
- Persistent session
- Directory tracking
📂 File Operations
- Upload file
- Download file
- Create file
👑 Root Mode
sudo -i execution
- Privilege escalation simulation
📦 Requirements
Install dependencies:
pip install requests dnspython
📥 Installation
1. Clone Repository
git clone https://github.com/yourusername/react2shell-cve-2025-55182.git
2. Masuk ke directory
cd react2shell-cve-2025-55182
python3 react2shell.py
🚀 Usage
🎯 Single Target
python3 react2shell.py -u https://target.com
Tanpa protocol:
python3 react2shell.py -u target.com
📄 Multiple Targets
python3 react2shell.py -f targets.txt
Contoh isi targets.txt:
https://target1.com
http://target2.com:3000
target3.com
🌐 Full Mode (Recon + Scan + Exploit)
python3 react2shell.py -d example.com
Flow:
- Subdomain enumeration
- Vulnerability scanning
- Exploitation (optional)
📚 Custom Wordlist
python3 react2shell.py -d example.com -w wordlist.txt
🐞 Debug Mode
python3 react2shell.py -d example.com --debug
🖥️ Interactive Shell
Setelah exploit berhasil, kamu akan mendapatkan akses shell.
Basic Commands
whoami
id
uname -a
pwd
ls -lah
⚙️ Special Commands
| Command | Description |
|---|
| .root | Toggle root mode |
| .upload | Upload file ke target |
| .download | Download file dari target |
| .create | Create file di target |
| .save | Save output ke file lokal |
| .exit | Exit shell |
📂 Upload File
.upload shell.php /tmp/shell.php
📥 Download File
.download /etc/passwd
📄 Create File
.create /tmp/test.txt
🔄 Example Workflow
1. Scan domain
python3 react2shell.py -d example.com
2. Identifikasi target vulnerable
3. Masuk shell
whoami
4. Upload payload
.upload backdoor.sh /tmp/backdoor.sh
📁 Output Files
Tool akan menghasilkan:
- subdomains_*.txt
- vulnerable_*.txt
- output_*.txt
⚠️ Impact
Jika berhasil dieksploitasi:
- Remote command execution
- Akses file sensitif
- Upload backdoor
- Persistence access
- Privilege escalation
🛡️ Mitigation
- Update Next.js ke versi terbaru
- Restrict endpoint internal
- Validasi input dengan ketat
- Gunakan WAF (OWASP CRS)
- Monitoring aktivitas anomali
⚠️ Disclaimer
Tool ini dibuat hanya untuk:
- Pembelajaran
- Research
- Authorized penetration testing
Dilarang digunakan untuk aktivitas ilegal.
⭐ Notes
Project ini menunjukkan:
- Advanced exploitation skill
- Pemahaman Next.js internals
- Simulasi serangan real-world