VDB
CVE-2025-55182
CVE-2025-55182
PUBLISHED
KEV
[CVE-2025-55182] Deserialization on vizss.czdt.smce.nasa.gov through /* via POST parameter "0" leads to Remote Code Execution (RCE)
EPSS 99.80% · 100.0th percentile
Risk Scores
EPSS Score
99.80%
100.0th percentile
Timeline
- CVE Published
- Jun 24, 2024 PoC Published
- Dec 3, 2025 VulnCheck KEV Exploitation
- Dec 4, 2025 VulnCheck KEV Exploitation
- Dec 4, 2025 PoC Published
- Dec 4, 2025 EPSS Score
- Dec 4, 2025 VulnCheck XDB Entry
- Dec 4, 2025 VulnCheck XDB Entry
- Dec 4, 2025 VulnCheck XDB Entry
- Dec 4, 2025 PoC Published
- Dec 5, 2025 VulnCheck KEV Exploitation
- Dec 5, 2025 PoC Published
References
- SECURITY VULNERABILITY REPORT (TXT VERSION) React2Shell CVE-2025-55182 advisory
- [CVE-2025-55182] Deserialization on vizss.czdt.smce.nasa.gov through /* via POST parameter "0" leads to Remote Code Execution (RCE) advisory
- Fastly’s Proactive Protection for React2Shell, Critical React RCE CVE-2025-55182 and CVE-2025-66478 third-party-analysis
- How React2Shell is evolving: Industries and regions targeted third-party-analysis
- React2Shell Continued: What to know and do about the 2 latest CVEs third-party-analysis
- Blog third-party-analysis
- Nuclei Template exploit