AWS: China-linked threat actors weaponized React2Shell hours after disclosure
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,理解其主要内容和关键点。 文章主要讲的是AWS安全团队警告称,与中国相关的威胁行为者在React2Shell漏洞披露后几小时内就开始利用它。这个漏洞是CVE-2025-55182,属于React Server Components中的一个预身份验证远程代码执行漏洞。虽然这个漏洞不影响AWS的服务,但AWS还是分享了威胁情报数据,帮助客户保护自己的React或Next.js应用。 文章还提到,这些威胁行为者包括Earth Lamia和Jackpot Panda,他们利用大型匿名化网络进行攻击,使得溯源变得困难。此外,攻击者使用自动化扫描器和PoC漏洞来快速整合公开的 exploits,并进行多CVE的广泛攻击。 接下来,我需要将这些信息浓缩到100字以内。重点包括:React2Shell漏洞、中国相关威胁行为者迅速利用、影响版本、攻击手段以及匿名化网络的使用。 可能的结构是:首先说明事件,然后说明影响范围和攻击手段。确保语言简洁明了,不使用复杂的术语。 最后检查字数是否符合要求,并确保信息准确无误。 </think> 中国关联的网络威胁行为者在React2Shell漏洞(CVE-2025-55182)披露后迅速利用该漏洞发起攻击。该漏洞存在于React Server Components特定版本中,允许未经身份验证的远程代码执行。尽管不影响AWS服务,但其研究人员仍分享情报以帮助客户应对风险。攻击活动与Earth Lamia和Jackpot Panda等中国关联团伙有关,并利用匿名化网络掩盖身份。 2025-12-8 13:37:42 Author: securityaffairs.com(查看原文) 阅读量:6 收藏

AWS: China-linked threat actors weaponized React2Shell hours after disclosure

Pierluigi Paganini December 08, 2025

Multiple China-linked threat actors began exploiting the CVE-2025-55182, aka React2Shell flaw, within hours, AWS Security warns.

Multiple China-linked threat actors began exploiting the CVE-2025-55182, also known as the React2Shell flaw, within hours, according to AWS Security. The researchers confirmed that this vulnerability doesn’t affect AWS services, however they opted to share threat intelligence data to help customers running React or Next.js applications in their own environments take immediate action.

The vulnerability is a pre-authentication remote code execution vulnerability in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The flaw comes from the code deserializing data from HTTP requests to Server Function endpoints without proper safety checks.

“A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack.” reads the advisory. “The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.”

The researcher Lachlan Davidson reported the security vulnerability in React on November 29th. He explained that unsafe payload decoding in Server Function endpoints allows unauthenticated code execution. Apps using React Server Components may be exposed even without Server Function endpoints.

Versions 19.0.119.1.2, and 19.2.1 addressed the flaw.

AWS Security observed exploitation attempts in AWS MadPot coming from infrastructure tied to China-linked groups Earth Lamia and Jackpot Panda. Earth Lamia typically exploits web app flaws to target organizations across LATAM, the Middle East, and Southeast Asia, while Jackpot Panda focuses on East and Southeast Asia for intelligence tied to security and corruption. Both operate through large shared anonymization networks widely used in Chinese cyber operations, which mask attacker identity and make precise attribution difficult.

“Our analysis of exploitation attempts in AWS MadPot honeypot infrastructure has identified exploitation activity from IP addresses and infrastructure historically linked to known China state-nexus threat actors.” reads the report published by AWS Security. “Large-scale anonymization networks have become a defining characteristic of Chinese cyber operations, enabling reconnaissance, exploitation, and command-and-control activities while obscuring attribution. These networks are used by multiple threat groups simultaneously, making it difficult to attribute specific activities to individual actors.”

Most unattributed activity uses China-linked ASNs, indicating the region as the main source. Groups rapidly weaponize public PoCs as soon as they appear online.

Threat actors use automated scanners and PoC exploits to target CVE-2025-55182 and other N-days like CVE-2025-1338, rapidly integrating public exploits and running broad multi-CVE campaigns. Many public PoCs are flawed, yet still used, reflecting a focus on speed, volume, and low entry barriers. Failed attempts create significant log noise, potentially masking more sophisticated attacks.

“Analysis of data from MadPot reveals the persistent nature of these exploitation attempts. In one notable example, an unattributed threat cluster associated with IP address 183[.]6.80.214 spent nearly an hour (from 2:30:17 AM to 3:22:48 AM UTC on December 4, 2025) systematically troubleshooting exploitation attempts.” concludes the report. “This behavior demonstrates that threat actors aren’t just running automated scans, but are actively debugging and refining their exploitation techniques against live targets.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)




文章来源: https://securityaffairs.com/185436/security/aws-china-linked-threat-actors-weaponized-react2shell-hours-after-disclosure.html
如有侵权请联系:admin#unsafe.sh