Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
react2shell-cve-2025-55182 — Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and interactive remote shell with file operations. | Kitploit
Tools/GitHubGitHub/opsecramdan/react2shell-cve-2025-55182
Privilege EscalationReconnaissanceVulnerability ScannersPayload GenerationExploitationWeb Application ExploitationPenetration TestingCommand and ControlSubdomain Enumeration

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Remote Access Tool
GitHubopsecramdan/react2shell-cve-2025-55182

react2shell-cve-2025-55182

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and interactive remote shell with file operations.

View Repository
215 months agoNot yet reviewed

🚨 React2Shell - CVE-2025-55182 Exploitation Framework

Severity Type Platform Python

Advanced exploitation framework for CVE-2025-55182 (Next.js Remote Code Execution)

Author: opsecramdan


📚 Table of Contents

  • Overview
  • Vulnerability Details
  • Features
  • Requirements
  • Installation
  • Usage
  • Interactive Shell
  • Output Files
  • Impact
  • Mitigation
  • Limitations
  • Disclaimer

📌 Overview

React2Shell adalah framework exploitation untuk mengidentifikasi dan mengeksploitasi vulnerability CVE-2025-55182 pada aplikasi berbasis Next.js.

Tool ini dirancang sebagai all-in-one offensive toolkit yang mencakup:

  • Subdomain enumeration
  • Vulnerability scanning
  • Exploitation engine
  • Interactive remote shell

🔍 Vulnerability Details

  • CVE ID: CVE-2025-55182
  • Type: Remote Code Execution (RCE)
  • Platform: Next.js
  • Attack Vector: Malicious multipart/form-data request
  • Impact: Arbitrary command execution

🧠 Root Cause

Vulnerability ini memanfaatkan mekanisme internal Next.js dengan cara:

  1. Inject payload ke request
  2. Memanggil: process.mainModule.require('child_process')
  3. Menjalankan command OS
  4. Encode output dalam Base64
  5. Leak hasil melalui redirect (/login?a=)

⚙️ Features

🔎 Subdomain Enumeration

  • DNS + HTTP scanning
  • Built-in wordlist
  • Custom wordlist support
  • Auto save result

🧪 Vulnerability Scanner

  • Multi-endpoint testing:
  • /
  • /api
  • /api/auth
  • /_next
  • /admin
  • /dashboard
  • Header & response analysis
  • False-positive reduction

💣 Exploitation Engine

  • Automatic payload generation
  • Base64 encoded execution
  • Redirect-based output extraction

🖥️ Interactive Shell

  • Remote command execution
  • Persistent session
  • Directory tracking

📂 File Operations

  • Upload file
  • Download file
  • Create file

👑 Root Mode

  • sudo -i execution
  • Privilege escalation simulation

📦 Requirements

  • Python 3.x

Install dependencies: pip install requests dnspython


📥 Installation

1. Clone Repository

git clone https://github.com/yourusername/react2shell-cve-2025-55182.git

2. Masuk ke directory

cd react2shell-cve-2025-55182

3. Jalankan tool

python3 react2shell.py


🚀 Usage

🎯 Single Target

python3 react2shell.py -u https://target.com

Tanpa protocol:

python3 react2shell.py -u target.com


📄 Multiple Targets

python3 react2shell.py -f targets.txt

Contoh isi targets.txt:

https://target1.com http://target2.com:3000 target3.com


🌐 Full Mode (Recon + Scan + Exploit)

python3 react2shell.py -d example.com

Flow:

  1. Subdomain enumeration
  2. Vulnerability scanning
  3. Exploitation (optional)

📚 Custom Wordlist

python3 react2shell.py -d example.com -w wordlist.txt


🐞 Debug Mode

python3 react2shell.py -d example.com --debug


🖥️ Interactive Shell

Setelah exploit berhasil, kamu akan mendapatkan akses shell.

Basic Commands

whoami
id
uname -a
pwd
ls -lah


⚙️ Special Commands

CommandDescription
.rootToggle root mode
.uploadUpload file ke target
.downloadDownload file dari target
.createCreate file di target
.saveSave output ke file lokal
.exitExit shell

📂 Upload File

.upload shell.php /tmp/shell.php


📥 Download File

.download /etc/passwd


📄 Create File

.create /tmp/test.txt


🔄 Example Workflow

1. Scan domain

python3 react2shell.py -d example.com

2. Identifikasi target vulnerable

3. Masuk shell

whoami

4. Upload payload

.upload backdoor.sh /tmp/backdoor.sh


📁 Output Files

Tool akan menghasilkan:

  • subdomains_*.txt
  • vulnerable_*.txt
  • output_*.txt

⚠️ Impact

Jika berhasil dieksploitasi:

  • Remote command execution
  • Akses file sensitif
  • Upload backdoor
  • Persistence access
  • Privilege escalation

🛡️ Mitigation

  • Update Next.js ke versi terbaru
  • Restrict endpoint internal
  • Validasi input dengan ketat
  • Gunakan WAF (OWASP CRS)
  • Monitoring aktivitas anomali

⚠️ Disclaimer

Tool ini dibuat hanya untuk:

  • Pembelajaran
  • Research
  • Authorized penetration testing

Dilarang digunakan untuk aktivitas ilegal.


⭐ Notes

Project ini menunjukkan:

  • Advanced exploitation skill
  • Pemahaman Next.js internals
  • Simulasi serangan real-world
Download Tool