HabrSeptember 11, 2026🇷🇺Translated from Russian

Exploiting CVE-2025-55182 React2Shell Vulnerability on Hack The Box Reactor Machine

A detailed technical walkthrough shows how the seasonal Hack The Box machine Reactor can be fully compromised by exploiting the critical Next.js deserialization vulnerability CVE-2025-55182, publicly known as React2Shell.

Initial reconnaissance with Nmap identifies an OpenSSH service on port 22 and a web application on port 3000. The application presents itself as a reactor monitoring dashboard built with an outdated version of the Next.js framework, confirmed via the Wappalyzer browser extension.

Searching for known issues immediately surfaces CVE-2025-55182, a 10.0 CVSS vulnerability that allows unauthenticated remote code execution through unsafe deserialization of HTTP request data. A public exploit repository is cloned and executed to obtain a reverse shell as the node user.

Further enumeration reveals the reactor.db SQLite database containing user password hashes. The hash belonging to the engineer account is cracked offline with Hashcat using the rockyou wordlist, enabling SSH login and retrieval of the user flag.

Privilege escalation is performed by discovering an active Node.js Inspector debug listener on port 9229 running as root. The websocat binary is transferred to the target, and a crafted WebSocket payload sets the SUID bit on /bin/bash, granting root privileges and access to the root flag.

The article concludes by noting that the vulnerability affected numerous React/Next.js applications in late 2025 and emphasizes the risks of leaving development debugging ports exposed on production servers.

Related articles

Security NEXTVulnerabilities & Exploits

CISA Adds MikroTik RouterOS Flaws CVE-2026-67277 and CVE-2026-86060 to Known Exploited Vulnerabilities Catalog

The US Cybersecurity and Infrastructure Security Agency has added two actively exploited vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities Catalog. CVE-2026-86060 stems from improper sanitization of command argument delimiters and can lead to privilege escalation after an attacker gains access to the SSH login helper and alters trusted policy masks. CVE-2026-67277 involves missing authentication checks in critical RouterOS functions, allowing connections before authentication completes and potentially leaking kernel memory or causing denial-of-service conditions. CISA directed US federal agencies to apply mitigations by September 13 and specifically investigate any signs of compromise related to CVE-2026-86060. The agency noted that the flaws carry broader exploitation risk and urged all organizations using affected MikroTik products to take immediate action.

HabrVulnerabilities & Exploits

The Birth of CVE: How Two MITRE Engineers Built the Universal Vulnerability Identifier in 1999

In the late 1990s, security teams faced chaos with one vulnerability carrying dozens of incompatible names across scanners, IDS tools, and CERT advisories. Two MITRE engineers, David E. Mann and Steven M. Christey, proposed a minimal Common Vulnerabilities and Exposures list to solve correlation problems without imposing taxonomy or risk models. Their January 1999 paper led to a Purdue workshop, the formation of the CVE Editorial Board, and a public launch on September 29, 1999, with 321 initial entries. The design deliberately avoided ownership by any vendor and kept names as simple CVE-year-number strings. This neutral, open approach allowed competing vendors to map their proprietary databases to a shared reference without agreeing on classifications. The same minimalist philosophy later influenced NVD, OSV, and GitHub Advisory Database.

AntiMalwareVulnerabilities & Exploits

OnePlus 13R Preinstalled Account App Leaks Cloud Session Tokens to Any App Declaring Required Permission

Researchers at Doyensec identified a vulnerability in the preinstalled com.oneplus.account application on the OnePlus 13R that allows any third-party app to steal a valid OnePlus Cloud session token. The flaw stems from the OPAccountProvider component lacking the protectionLevel="signature" attribute on its declared permission com.oneplus.account.READ_ACCOUNT_INFO, enabling any app to request the permission and query the provider directly. Once obtained, the token grants access to OnePlus Cloud APIs without further user interaction or warnings. Doyensec responsibly disclosed the issue on 30 December 2025, leading OnePlus to acknowledge the high-severity problem and pay a $720 bounty in March 2026. Follow-up testing in September on firmware CPH2691_16.0.10.500(EX01) confirmed the token leakage persists, although full account takeover via the regional API was no longer reproducible for US and EMEA accounts due to backend changes. Users are advised to avoid untrusted apps and apply future updates, while OnePlus needs only to add the signature protection level to close the exposure.

BoletimSecVulnerabilities & Exploits

Microsoft Fixes Remote Code Execution Flaw in Windows Remote Desktop Client

Microsoft has addressed a remote code execution vulnerability in the Windows Remote Desktop Client tracked as CVE-2026-69485 with a CVSS score of 8.8. The flaw stems from the use of an uninitialized resource and can be triggered by a specially crafted network request from an authenticated attacker with low privileges. Exploitation requires no user interaction such as clicking links or opening files and can lead to information disclosure, file modification, or service disruption. Multiple versions of Windows 10, Windows 11, and Windows Server 2016 through 2025 are affected, including Server Core installations. The issue was not publicly disclosed prior to patching and no active exploitation has been observed. Fixes were released in the September security updates including KB5124008 and KB5122871.