Home / CVE DB / CVE-2025-55182
Standard
Vulnerability Identifier

CVE-2025-55182

2025-12-03
Severity Assessment
10.0
CRITICAL
CVSS v3.x Score

CISA KEV Active Alert

Date Added
01 Jan 1970
Due Date
N/A
Required Action
Apply updates per vendor instructions.
Clinical Analysis (Description)

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

Vector Sequencing

Attack Parameters

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Impact Consequences

Technical Impact

Changed
Scope
High
Confidentiality
High
Integrity
High
Availability
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Classification

CWE-CWE-502

Affected Population

Affected Configurations

Total: 7 detected entries

Software List Scrollable
ve
next.js
Vendor: vercel • v15.6.0
ve
next.js
Vendor: vercel • v16.0.0
fa
react
Vendor: facebook • v19.2.0
fa
react
Vendor: facebook • v19.0.0
fa
react
Vendor: facebook • v19.1.0
ve
next.js
Vendor: vercel • v14.3.0
fa
react
Vendor: facebook • v19.1.1
Timeline

Time Line

PUBLICATION
03 Dec 2025
MODIFICATION
10 Dec 2025
FIRST PATCH
21 Apr 2026
Impact Statistics

Key Metrics

CVSS Score
10.0
CRITICAL
Products
7
Affected
Patches
2
Available
Articles
3
Published
Active Exploitation Confirmed
Public Exploit Available
Remediation Protocol

Recommended Solution

No automatic solution found. Check vendor references.
Associated Cyber Intelligence

Related News Articles

3 article(s) mentioning this vulnerability

Article #1

RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers

Cybersecurity researchers have disclosed a persistent nine-month-long campaign targeting IoT devices and web applications, leveraging the React2Shell (CVE-2025-55182) flaw as…

7
02 Jan 2026 vulnerability HIGH
Article #2
7

RondoDox Botnet Exploits React2Shell Flaw to Infect Next.js Servers

RondoDox botnet exploits React2Shell flaw (CVE-2025-55182) to infect Next.js servers with malware and cryptominers.

02 Jan 2026 vulnerability HIGH
Article #3

RondoDox Botnet Exploits React2Shell Flaw to Compromise Next.js Servers

RondoDox botnet exploits React2Shell flaw to infect Next.js servers with malware and cryptominers.

7
02 Jan 2026 vulnerability HIGH
Recommended Actions for Administrators

Immediate Action Plan

1. Inventory

Identify all affected systems in your infrastructure.

2. Assessment

Assess exposure and criticality for your organization.

3. Mitigation

Apply patches or available workarounds.

4. Verification

Test and confirm effectiveness of applied measures.

⚠️ MAXIMUM PRIORITY - Immediate action required