Mass exploitation campaign hits critical React Server Components flaw

GreyNoise has observed an active campaign exploiting CVE-2025-55182 in React Server Components. The vulnerability allows remote code execution and carries a CVSS score of 10.0. It was published on 3 December last year. Two IP addresses dominate the traffic: 193.142.147[.]209 attempts to establish reverse shells, while 87.121.84[.]24 attempts to deploy cryptominers.

What this means for your organisation

React underpins a great many Norwegian web and customer portals, and server components typically run on machines with access to databases and internal services. When a flaw of this severity is exploited at scale, the question is no longer whether someone is looking for you. What matters is the gap between a published fix and an actually patched production environment, and that gap is now being targeted.

Berigo recommends

  • Map which applications in your portfolio actually use React Server Components, including vendor-supplied solutions.
  • Upgrade to the patched version now, ahead of your ordinary change calendar.
  • Search historical logs for the two IP addresses listed, not just block them going forward.
  • Look for unexpected outbound connections and unusual CPU load on web servers as signs of reverse shells or mining activity.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch