Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityrapid-weaponizationinternet-facing-service-vulnerabilitythreat-infrastructure-tracking

GreyNoise Reports Concentrated Exploitation of React Server Components RCE (CVE-2025-55182)

Updated 3mo agoFirst seen Feb 4, 20262 sources

GreyNoise telemetry indicates that exploitation of CVE-2025-55182 in React Server Components has shifted from broad, opportunistic scanning to concentrated, high-volume campaigns. The flaw is described as pre-authentication RCE with a CVSS 10.0 and can be triggered via a single malicious HTTP POST request, making exposed development servers (notably on ports 3000–3002 in addition to 80/443) attractive targets. Between Jan 26 and Feb 2, 2026, GreyNoise observed 1,083 unique sources attempting exploitation, but two IPs accounted for 56% of observed activity, suggesting industrialized automation rather than ad-hoc testing.

Reporting attributes 34% of sessions to 193.142.147[.]209, associated with payloads that open reverse shells back to the scanning host (including use of port 12323), indicating intent for interactive access and potential follow-on pivoting. Another 22% is attributed to 87.121.84[.]24, linked to cryptomining activity (e.g., downloading XMRig from staging infrastructure); one cited staging host is 205.185.127[.]97, associated with attacker-controlled domains (e.g., mased[.]top, mercarios[.]buzz) and adjacent subnet activity reportedly distributing Mirai. Separately, GreyNoise also reported a distinct reconnaissance campaign against Citrix NetScaler/Gateway using tens of thousands of residential proxy IPs to enumerate login panels and version artifacts (e.g., /logon/LogonPoint/index.html and /epa/scripts/win/nsepa_setup.exe), which appears to be pre-exploitation mapping and is not directly tied to the React CVE activity.

Share:
GreyNoise Reports Concentrated Exploitation of React Server Components RCE (CVE-2025-55182)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 4, 20265mo ago

GreyNoise warns exposed, unpatched React systems should be assumed targeted

Following the observed surge in exploitation, GreyNoise warned that organizations running unpatched React Server Components should assume they had been targeted. Defenders were urged to upgrade to fixed React versions or restrict exposure of development ports and unsafe bindings such as 0.0.0.0.

Public Metasploit module released for CVE-2025-55182

A public Metasploit module became available for CVE-2025-55182, enabling pre-authentication RCE via a single malicious HTTP POST request. Its availability increased automation and lowered the barrier to exploitation.

Jan 26, 20265mo ago

Attackers deploy cryptominers and reverse shells via React flaw

GreyNoise reported that one major campaign used the vulnerability to download and run XMRig cryptomining payloads, while another established reverse shells for interactive control and possible pivoting. The activity targeted common web ports and React development defaults such as ports 3000 through 3002.

GreyNoise observes concentrated exploitation campaigns

Between January 26 and February 2, 2026, GreyNoise telemetry showed exploitation shifting from broad scanning to concentrated, industrial-scale activity. Although 1,083 unique sources probed for the flaw, two IP addresses accounted for 56% of observed malicious sessions.

Dec 4, 20257mo ago

CVE-2025-55182 disclosed in React Server Components

A critical unauthenticated remote code execution flaw, CVE-2025-55182, affecting multiple React 19.x versions was publicly disclosed. The bug was described as an insecure deserialization issue with maximum severity (CVSS 10.0).

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Vulnerabilities
1 linked
Malware
3 linked
Affected products
3 linked
ReactMetasploit FrameworkNext.Js
Organizations
1 linked
GreyNoise
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.