Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
cve-2025-55182-scanner — CVE-2025-55182 및 CVE-2025-66478을 위한 수동 취약점 스캐너로, 프레임워크 핑거프린팅, 버전 분석, RSC 엔드포인트 프로빙을 통해 React Server Components의 인증되지 않은 RCE를 탐지합니다. | Kitploit
도구/GitHubGitHub/xkillbit/cve-2025-55182-scanner
Vulnerability ScannersExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubxkillbit/cve-2025-55182-scanner

cve-2025-55182-scanner

CVE-2025-55182 및 CVE-2025-66478을 위한 수동 취약점 스캐너로, 프레임워크 핑거프린팅, 버전 분석, RSC 엔드포인트 프로빙을 통해 React Server Components의 인증되지 않은 RCE를 탐지합니다.

저장소 보기
41110개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2025-55182 / CVE-2025-66478 취약점 스캐너

React Server Components Flight 프로토콜 원격 코드 실행 탐지 도구

CVSS Score Disclosure Date License


요약

이 스캐너는 React Server Components(RSC) "Flight" 프로토콜의 심각한 무인증 원격 코드 실행 취약점인 CVE-2025-55182(React) 및 CVE-2025-66478(Next.js)에 잠재적으로 취약한 시스템을 식별합니다.

주요 위험 요소:

  • CVSS 10.0 - 최대 심각도
  • 무인증 - 로그인 불필요
  • 원격 - 네트워크를 통해 악용 가능
  • 기본 구성에도 영향
  • 악용 신뢰도가 거의 100%로 보고됨

목차

  1. 취약점 개요
  2. 스캐너 작동 방식
  3. 설치
  4. 사용법
  5. 결과 이해
  6. 신뢰 수준
  7. 제한 사항
  8. 권장 사항
  9. 참조

취약점 개요

CVE-2025-55182란 무엇인가요?

React의 Server Components 구현에서 발생하는 심각한 안전하지 않은 역직렬화(insecure deserialization) 취약점입니다. RSC "Flight" 프로토콜이 수신 페이로드의 구조와 유형을 제대로 검증하지 못하여, 공격자가 서버 측 실행에 영향을 미치는 악성 데이터를 주입할 수 있습니다.

영향을 받는 구성 요소

패키지취약한 버전패치된 버전
react-server-dom-webpack19.0.0, 19.1.0, 19.1.1, 19.2.019.0.1, 19.1.2, 19.2.1
react-server-dom-parcel19.0.0, 19.1.0, 19.1.1, 19.2.019.0.1, 19.1.2, 19.2.1
react-server-dom-turbopack19.0.0, 19.1.0, 19.1.1, 19.2.019.0.1, 19.1.2, 19.2.1
Next.js14.3.0-canary.77+, 15.x, 16.0.0-16.0.615.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7

영향을 받는 프레임워크

  • Next.js (App Router)
  • React Router (RSC 미리보기)
  • Vite RSC 플러그인
  • Parcel RSC 플러그인
  • RedwoodJS (RedwoodSDK)
  • Waku

공격 경로

Attacker → Crafted HTTP POST → RSC Endpoint → Deserialization → RCE

공격에는 임의의 서버 함수(Server Function) 엔드포인트에 대한 특수하게 조작된 HTTP 요청 하나만 필요합니다. 인증이 필요하지 않으며 기본 구성도 취약합니다.


스캐너 작동 방식

탐지 방법론

스캐너는 수동적 핑거프린팅(passive fingerprinting) 및 **프로토콜 프로빙(protocol probing)**을 사용하여 잠재적으로 취약한 시스템을 식별합니다. 실제 악용은 시도하지 않습니다.

┌─────────────────────────────────────────────────────────────────┐
│                     DETECTION PIPELINE                          │
├─────────────────────────────────────────────────────────────────┤
│                                                                 │
│  1. Framework Detection                                         │
│     ├── HTTP Headers (X-Powered-By: Next.js)                   │
│     ├── Page Source (__NEXT_DATA__, react artifacts)           │
│     └── Build Manifests                                         │
│                                                                 │
│  2. Version Fingerprinting                                      │
│     ├── Embedded version strings in JS bundles                 │
│     ├── Package version patterns                                │
│     └── Build manifest analysis                                 │
│                                                                 │
│  3. RSC Endpoint Discovery                                      │
│     ├── Send RSC headers (RSC: 1, Accept: text/x-component)    │
│     ├── Analyze response Content-Type                          │
│     └── Detect Flight protocol markers in response             │
│                                                                 │
│  4. Server Actions Probing                                      │
│     ├── POST request with minimal Flight payload               │
│     ├── Check for deserialization processing                   │
│     └── Identify action endpoints                              │
│                                                                 │
│  5. Vulnerability Assessment                                    │
│     ├── Correlate version with known vulnerable ranges         │
│     ├── Weight RSC endpoint presence                           │
│     └── Generate confidence-scored verdict                     │
│                                                                 │
└─────────────────────────────────────────────────────────────────┘

기술적 탐지 방법

1. 프레임워크 탐지

지표탐지 방법신뢰도
X-Powered-By: Next.jsHTTP 헤더 검사높음
__NEXT_DATA__ 스크립트 태그HTML 소스 파싱높음
/_next/ 에셋 경로HTML 소스 파싱중간
React 하이드레이션 마커HTML 소스 파싱중간

2. RSC 프로토콜 탐지

Flight 프로토콜은 특정한 와이어 포맷을 사용합니다:

0:["$","div",null,{"children":"Hello"}]
1:["$","$L1",null,{}]
2:{"name":"ServerComponent"}

스캐너는 다음을 찾습니다:

  • text/x-component 콘텐츠 유형
  • 청크 형식: {number}:{payload}
  • 참조 마커: $, $L, $F, $@, $undefined

3. 버전 핑거프린팅

다음 위치에서 버전 패턴을 검색합니다:

  • JavaScript 번들 (/_next/static/chunks/)
  • 빌드 매니페스트
  • 인라인 스크립트
  • 패키지 참조 ([email protected])

설치

요구 사항

  • Python 3.8+
  • requests 라이브러리

설정

# Clone or download the scanner files
# Install dependencies
pip install -r requirements.txt

# Verify installation
python3 cve-2025-55182-scanner.py --help

사용법

기본 스캔

# Single target
python3 cve-2025-55182-scanner.py -t https://example.com

# With verbose output
python3 cve-2025-55182-scanner.py -t https://example.com -v

일괄 스캔

# Create targets file (one URL per line)
echo "https://app1.example.com" > targets.txt
echo "https://app2.example.com" >> targets.txt

# Scan all targets
python3 cve-2025-55182-scanner.py -f targets.txt -o results.json

고급 옵션

python3 cve-2025-55182-scanner.py -t https://example.com \
    --timeout 15 \
    --threads 10 \
    --user-agent "SecurityAudit/1.0" \
    -v \
    -o scan_results.json

명령줄 옵션

옵션설명기본값
-t, --target단일 대상 URL-
-f, --file대상 목록 파일-
-o, --outputJSON 출력 파일-
-v, --verbose상세 증거 표시False
--timeout요청 시간 제한(초)10
--threads동시 스레드 수5
--verify-sslSSL 인증서 확인False
--user-agent사용자 지정 User-AgentMozilla/5.0...
--no-banner배너 숨기기False

RSC 분석기 모듈 사용

더 심층적인 프로토콜 분석을 위해:

python3 rsc_analyzer.py https://example.com 2>/dev/null

이 모듈은 상세한 Flight 프로토콜 분석과 구성 요소 열거를 제공합니다.


결과 이해

상태 범주

상태의미필요한 조치
🔴 VULNERABLE취약한 버전 감지 확인됨즉시 패치
🔴 LIKELY_VULNERABLERSC가 포함된 React 19.x, 취약 범위 내 버전긴급 패치
🟡 POTENTIALLY_VULNERABLERSC 엔드포인트 발견, 버전 불명조사 및 패치
🟢 NOT_VULNERABLE패치된 버전 확인됨업데이트 모니터링
🔵 UNKNOWN상태 확인 불가수동 검증 필요
⚪ ERROR스캔 실패재시도 또는 수동 확인

예시 출력

======================================================================
Target: https://app.example.com
Status: VULNERABLE
Framework: Next.js
Version: 19.1.0
RSC Endpoints: /, /_next/data

Evidence:
  - X-Powered-By header: Next.js
  - React version detected: 19.1.0
  - RSC Flight response at / (Content-Type: text/x-component)
  - Flight protocol markers detected at /

Recommendations:
  → CRITICAL: Immediate patching required!
  → Upgrade React to 19.0.1, 19.1.2, or 19.2.1
  → Upgrade Next.js to latest patched version (15.0.5+, 16.0.7)
  → Enable WAF rules to block malicious RSC payloads
  → Monitor for anomalous POST requests to RSC endpoints
======================================================================

JSON 출력 형식

{
  "target": "https://app.example.com",
  "status": "VULNERABLE",
  "framework": "Next.js",
  "version": "19.1.0",
  "rsc_endpoints": ["/", "/_next/data"],
  "evidence": [
    "X-Powered-By header: Next.js",
    "React version detected: 19.1.0",
    "RSC Flight response at / (Content-Type: text/x-component)"
  ],
  "recommendations": [
    "CRITICAL: Immediate patching required!",
    "Upgrade React to 19.0.1, 19.1.2, or 19.2.1"
  ]
}

신뢰 수준

결과를 얼마나 신뢰해야 하나요?

도구 다운로드