
🔥 React2Shell Toolkit - CVE-2025-55182 & CVE-2025-66478
🚨 RCE Crítica em React Server Components e Next.js 🚨
Kit de Red Team profissional para detecção e exploração da CVE-2025-55182
React2Shell é uma vulnerabilidade crítica de Execução Remota de Código (RCE) não autenticada que afeta React Server Components (RSC) e aplicações Next.js.
| CVE ID | Componente | Pontuação CVSS |
|---|
// Attacker sends malicious Flight protocol payload
POST / HTTP/1.1
Next-Action: exploit
Content-Type: multipart/form-data
{"__proto__": "pollution", "then": "gadget_chain"}
↓
Unsafe Deserialization
↓
Prototype Pollution
↓
💥 Remote Code Execution 💥
|
🔓 Exploração de RCE Bem-sucedida
Execução de comandos via vulnerabilidade React2Shell |
⚠️ Estas capturas de tela demonstram exploração real em ambientes controlados
Use com responsabilidade e somente com autorização adequada
Este repositório contém 4 ferramentas de nível profissional para detecção e exploração da CVE-2025-55182:
# Clone the repository
git clone https://github.com/cybertechajju/R2C-CVE-2025-55182-66478.git
cd R2C-CVE-2025-55182-66478
# Install Python dependencies
pip install -r requirements.txt
pip install -r exploits/requirements.txt
# Scan single target
nuclei -t nuclei-templates/cve-2025-55182.yaml -u https://target.com
# Scan multiple targets
nuclei -t nuclei-templates/cve-2025-55182.yaml -l targets.txt
# Interactive wizard mode
python exploits/shodan_scanner_advanced.py
# Or with API key directly
python exploits/shodan_scanner_advanced.py --api YOUR_SHODAN_API_KEY
# Interactive mode
bash exploits/scanner_advanced.sh -i
# Quick exploitation
bash exploits/scanner_advanced.sh -d https://target.com -p 2
burp-extension/React2Shell_Burp.pycve-2025-55182/
├── 📂 nuclei-templates/ # Nuclei YAML templates
│ └── cve-2025-55182.yaml # Advanced detection template
├── 📂 exploits/ # Exploitation tools
│ ├── shodan_scanner_advanced.py # Shodan mass scanner
│ ├── scanner_advanced.sh # Bash exploitation framework
│ └── requirements.txt # Python dependencies
├── 📂 burp-extension/ # Burp Suite extension
│ ├── React2Shell_Burp.py # Main extension (30+ payloads)
│ ├── payloads.json # Payload library
│ └── detection_rules.json # Detection patterns
├── 📂 burp bechek/ # BCheck files for Burp Scanner
│ ├── CVE-2025-55182-React2Shell-Active.bcheck
│ └── CVE-2025-66478-NextJS-React2Shell-Active.bcheck
└── 📄 README.md # This file
41 * 271 = 11111 (zero falsos positivos)╔═══════════════════════════════════════════════════════════════╗
║ ⚠️ CRITICAL WARNING ⚠️ ║
╚═══════════════════════════════════════════════════════════════╝
This toolkit is for AUTHORIZED SECURITY TESTING ONLY.
⚖️ Legal Use:
✅ Penetration testing with written authorization
✅ Bug bounty programs within defined scope
✅ Security research on owned infrastructure
✅ Educational purposes in controlled labs
❌ Illegal Activities:
⛔ Unauthorized system access
⛔ Malicious exploitation
⛔ Data theft or destruction
⛔ Deploying malware
By using this toolkit, you agree to use it ethically and legally.
Unauthorized access to computer systems is illegal under:
• Computer Fraud and Abuse Act (CFAA) - USA
• Computer Misuse Act - UK
• Similar laws worldwide
🔒 You are solely responsible for your actions.
Pesquisador de Segurança • Especialista em Red Team • Caçador de Bug Bounty
Lema: Continue Aprendendo, Continue Hackeando 🚀
Se este kit ajudou você, por favor ⭐ dê uma estrela neste repositório!
Somente para Testes de Segurança Educacionais e Autorizados
Nenhuma garantia ou responsabilidade é fornecida. Use por sua conta e risco.
Abra uma Issue ou entre em contato pelas redes sociais!
Feito com ❤️ por CyberTechAjju
Continue Aprendendo. Continue Hackeando. Mantenha-se Ético. 🎯🔐
| Impacto |
|---|
| CVE-2025-55182 | React Server Components | 10.0 🔴 | Assunção Total do Servidor |
| CVE-2025-66478 | Next.js Server Actions | 10.0 🔴 | Comprometimento Total do Sistema |
|
💥 Confirmação da Vulnerabilidade
Comprometimento do servidor por meio do protocolo Flight |
🔍 Template NucleiScanner Avançado ✅ 5 Payloads |
🐍 Scanner ShodanDescoberta de Alvos ✅ Busca Automatizada |
💻 Bash ExploitFramework de CLI ✅ 8 Payloads Predefinidos |
🔧 Extensão BurpTeste Manual ✅ 30+ Payloads |
|
|
|
|
|
|
|
| |