CVE-2025-55182 Exploitation Hits the Smart Home
Cybersecurity Classified by Officially
Shortly after details of CVE-2025-55182 became public, we began noticing large volumes of exploitation attempts across our endpoint and network sensors. The vulnerability, informally referred to as React2Shell, affects Node.js applications that allow user-supplied JSON data to influence internal JavaScript object structures. When improperly validated, attackers can escalate this into remote command execution through access to process.mainModule.require and, subsequently, child_process.execSync.
Read the original at the source: https://www.bitdefender.com/en-us/blog/labs/cve-2025-55182-exploitation-hits-the-smart-home
Officially imported this from Bitdefender’s own source. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Bitdefender — imported from official source
- Official source
- https://www.bitdefender.com/blog/api/rss/labs/ RSS
- Imported
- September 20, 2026 19:52
- Versions
- 1 recorded
- Identity
6937f928a89a0404d6eab153