
2025幎12æãReact Server ComponentsïŒRSCïŒã«ãããŠãªã¢ãŒãã³ãŒãå®è¡ïŒRCEïŒãåŒãèµ·ããæãã®ããèåŒ±æ§ CVE-2025-55182ïŒReact2ShellïŒ ãå ¬éãããŸãããå ¬éçŽåŸãããè€æ°ã®ã»ãã¥ãªãã£äŒæ¥ãã¹ãã£ãã³ã°æŽ»åãæªçšè©Šè¡ãšæšå®ãããæåã芳枬ãããšå ±åããŠãããCISA ããã®è匱æ§ãKnown Exploited VulnerabilitiesïŒKEVïŒ ãªã¹ãã«è¿œå ããŸããã
React2Shell ã¯ç¹å®ã®ãã¬ãŒã ã¯ãŒã¯åºæã®åé¡ã§ã¯ãªããReact ãšã³ã·ã¹ãã å šäœã«å ±éãã RSC æ©èœã®æ§é çæ¬ é¥ã«èµ·å ããè匱æ§ã§ããæ¬ã¬ããŒãã§ã¯ãReact2Shell ã®æè¡çæ§é ãRSC ããŒã¹ã®ãµãŒãã¹ã«ãããé²åºç¶æ³ã芳枬ãããæ»æååããããŠå®è·µçãªå¯Ÿå¿æŠç¥ã«ã€ããŠè§£èª¬ããŸãã
React2Shell è匱æ§ã®æŠèŠïŒèªèšŒãªãã§ RCE ãå¯èœã«ãªãæ§é çæ¬ é¥

CVE-2025-55182 ã¯ãReact Server Components ããµãŒããŒãšã¯ã©ã€ã¢ã³ãéã§ç¶æ ã亀æããéã«å©çšãã Flight ãããã³ã«ã®éã·ãªã¢ã«ååŠçã«ãããæ€èšŒäžå ã«èµ·å ããŸããæ»æè ã¯ãèªèšŒãªãã«æ¹ããããããã€ããŒãã Server Functions ã®ãšã³ããã€ã³ããžéä¿¡ããã ãã§ RCE ãå®è¡å¯èœã§ãããPoC ãå ¬éãããŠãããããèªååãããæ»æã«éåžžã«æãããããç¶æ³ã§ãã
圱é¿ç¯å²ã¯ RSC ãå©çšãããã¹ãŠã®ãµãŒãã¹ã«åã³ãç¹ã« Next.jsãReact Router RSCãWakuãVite RSC PluginãParcel RSC PluginãRedwoodJS ãªã©å€ãã®ãã¬ãŒã ã¯ãŒã¯ãåäžæ§é ãæ¡çšããŠããããšããããšã³ã·ã¹ãã å šäœã«åœ±é¿ããå¯èœæ§ããããŸãã
å ¬åŒããã㯠react-server-dom- ç³»ããã±ãŒãž 19.0.1 / 19.1.2 / 19.2.1 以äžã®ããŒãžã§ã³ããæäŸãããæ·±å»åºŠã¯ CVSS 10.0 ã«åé¡ãããæé«ã¬ãã«ã®é倧ãªè匱æ§ãšããŠæ±ãããŠããŸãã
Criminal IPã«ãã React2Shell é²åºè³ç£ã®æ€åºçµæ
React2Shell ã¯ãåŸæ¥ã® Web ãµãŒããŒã® Product æ
å ±ã HTML ã³ã³ãã³ãè§£æã®ã¿ã§ã¯æ€åºãå°é£ã§ããReact ããŒã¹ã®ãµãŒãã¹ã¯ãRSC ã³ã³ããŒãã³ããå€éšã«çŽæ¥é²åºããªãæ§é ãšãªã£ãŠãããç¹ã« Next.js ã®ããã« React ã¢ãžã¥ãŒã«ãå
éšã§ãã³ãã«ãããã¬ãŒã ã¯ãŒã¯ã§ã¯ãæè¡ã¹ã¿ãã¯ã®ç¹å®èªäœã容æã§ã¯ãããŸããããã®ãããåçŽãªãããŒæ
å ±ã«ããæ€åºæ¹æ³ã§ã¯ RSC ã®æå¹åç¶æ³ããè匱ãªå
¬éè³ç£ãæ£ç¢ºã«ææ¡ããããšã¯å°é£ã§ãã
å®éã®éçšç°å¢ã§ã¯ãHTTP ã¬ã¹ãã³ã¹ããããŒãåºç€ãšããè奿¹æ³ãæãä¿¡é Œæ§ã®é«ãæ€åºææ³ã§ããããšãåãããŸãããRSC ãæå¹åããããµãŒããŒã§ã¯ã以äžã®ããããŒç¹æ§ãå ±éããŠèŠ³æž¬ãããŸãã
Criminal IP Search Query: âVary: RSC, Next-Router-State-TreeâÂ
Criminal IP ã§ã¯ããããã®ææšãåºã«ã以äžã®ã¯ãšãªã䜿çšããŠ æ¥æ¬å°åã«ããã RSC æå¹ãµãŒããŒãæ€åºããããšãã§ããŸãã
Criminal IP Search Query: Â âVary: RSC, Next-Router-State-Treeâ country: âJPâ

Criminal IP ITè³ç£æ€çŽ¢ã®çµæã«ãããšã âVary: RSC, Next-Router-State-Treeâ country: âJPâ ã¯ãšãªã«åºã¥ãæ€çŽ¢ã§ã¯ãåèš 18,338 ä»¶ã® RSC è³ç£ãæ€åºãããŸããã
ãã㯠RSC ãæå¹åãããŠããããšã瀺ãèå¥å€ã§ãããæ€åºããããµãŒããŒããã¹ãŠè匱ã§ããããšãæå³ããããã§ã¯ãããŸãããããããå€§èŠæš¡ãªé²åºæ»æå¯Ÿè±¡é åãååšããããšã確èªã§ããéèŠãªææšãšãªããŸãã

Criminal IP ã§ç¢ºèªããç¹å®è³ç£ã®åæçµæãèŠããšãåœè©²ãµãŒããŒã¯ 80ã»443 ããŒããå€éšã«éæŸããŠãããå¿çããããŒãSSL èšŒææžæ
å ±ãè匱æ§äžèЧãããã« Exploit DB ãšã®é£æºæ
å ±ãŸã§ããããŒãžäžã§çµ±åçã«ç¢ºèªã§ããŸããã
ãã®è³ç£ã§ã¯ React2Shell ã«é¢é£ãããªã¹ã¯ã·ã°ãã«ã ãã§ãªããéå»ã«å€§èŠæš¡ãª DDoS æ»æã§æªçšããã CVE-2023-44487ïŒHTTP/2 Rapid ResetïŒ ãªã©ã®é倧ãªè匱æ§ãåæã«æ€åºãããŠããŸãã
ãã®ããã«ãCriminal IP ITè³ç£æ€çŽ¢ ã¯æ»æè ãæªçšããããç°å¢ãã©ãããå®éã®èгç¹ããè©äŸ¡ã§ãããããè€æ°ã®åæèŠçŽ ãæäŸããŠããŸãã
ã»ãã¥ãªãã£å¯Ÿå¿æ¹é
1. React é¢é£ããã±ãŒãžã®å³æã¢ããããŒã
以äžã®ããã±ãŒãžã¯ãå¿ ãææ°ãããããŒãžã§ã³ãžæŽæ°ããå¿ èŠããããŸãã
| ããã±ãŒãž | ãããé©çšããŒãžã§ã³ |
|---|---|
| react-server-dom-webpack | 19.0.1 / 19.1.2 / 19.2.1 |
| react-server-dom-parcel | 19.0.1+ |
| react-server-dom-turbopack | 19.0.1+ |
2. ãã¬ãŒã ã¯ãŒã¯å¥ã®ãããé©çšæç¡ã®ç¢ºèª
React RSC 㯠Next.jsãViteãParcelãRedwoodJS ãªã©ãè€æ°ã®ãã¬ãŒã ã¯ãŒã¯ã§å©çšãããŠããŸããç¹ã«Next.js 㯠RSC ãå
éšã«ãã³ããªã³ã°ïŒçµã¿èŸŒã¿ïŒããŠãããããåã« React ããã±ãŒãžãæŽæ°ããã ãã§ã¯ãè匱æ§ããããèªåçã«é©çšãããªãå¯èœæ§ããããŸãã
ãã®ãããåãã¬ãŒã ã¯ãŒã¯ãå
¬éããŠãã ã»ãã¥ãªãã£ã¢ããã€ã¶ãªããã³ãªãªãŒã¹ããŒããå¥é確èªããè匱æ§ãä¿®æ£ãããææ°ããŒãžã§ã³ãžã¢ããã°ã¬ãŒãããããšãå¿
é ã§ãã
3. RSC ãšã³ããã€ã³ãã®å€éšé²åºãæå°å
å¯èœãªå Žåã¯ãReverse ProxyïŒWAFãèªèšŒã²ãŒããŠã§ã€çïŒãå©çšããŠã¢ã¯ã»ã¹ãå¶éããŠãã ããã
4. Criminal IP ãæŽ»çšããã¢ãã¿ãªã³ã°
- RSCããããŒé²åºã®ç¶ç¶ã¢ãã¿ãªã³ã°
- TLSãã£ã³ã¬ãŒããªã³ãã«ããã¹ãã£ãã³ã°æŽ»åæ€ç¥
- æªæ§ã¹ãã£ãã³ã°IPã®èªåãããã¯
- è匱æ§ã®ååšæç¡ãš Exploit DB 飿ºç¶æ ã®ç¢ºèª
FAQ
Q1. ãVary: RSCããå«ãŸããŠãããã¹ãŠã®ãµãŒãã¹ãè匱ãªã®ã§ããããïŒ
ãVary: RSCããšããããããŒã¯ããµãŒããŒã React Server Components ã«åºã¥ããŠã¬ã³ããªã³ã°ãè¡ã£ãŠããããšãç€ºãæ å ±ã§ãããããã ãã§è匱æ§ã®æç¡ã倿ã§ããããã§ã¯ãããŸãããå®éã®ãªã¹ã¯ã¯ãReact é¢é£ã®ã»ãã¥ãªãã£ããããé©åã«é©çšãããŠãããã©ããã«ãã£ãŠæ±ºãŸããŸãããã ãããã®ããããŒã¯æ»æè ã RSC ãæå¹åããŠãããµãŒããŒãèŠã€ããããã®æããããšããŠå©çšãããå¯èœæ§ããããŸãã
Q2. HTMLãèŠãŠã React ã䜿çšããŠãããã©ããåããã«ããçç±ã¯äœã§ããããïŒ
React Server Components ã¯ãµãŒããŒå éšã§åŠçãè¡ãããããããã®æ§é ã HTML ã«çŽæ¥è¡šããŸããããŸããNext.js ã React ã¯ãã«ãæã«ã³ãŒããæé©åããä»çµã¿ããããå€éšãããã¬ãŒã ã¯ãŒã¯ç¹æã®ç¹åŸŽãèŠã€ãã«ããæ§é ã«ãªã£ãŠããŸãããã®ãããHTML ã®å 容ã ãã§ã¯ React ã RSC ã®å©çšæç¡ã倿ããããšã¯é£ãããå®éã®èå¥ã«ã¯ HTTP ã¬ã¹ãã³ã¹ããããŒãåæããæ¹æ³ã广çã§ãã
çµè«
React2ShellïŒCVE-2025-55182ïŒã¯ãWeb çæ ç³»ã§æãåºãå©çšãããŠãã React ããŒã¹ã®ãµãŒãã¹ã«åœ±é¿ãäžããé倧ãªè匱æ§ã§ãããæ»æé£æåºŠãäœããPoC ãå ¬éãããŠããããéåžžã«éãéåºŠã§æªçšãé²ãã§ããŸãã
Criminal IP ã®åæã«ãããšãæ¥æ¬åœå ã ãã§çŽ 18,000 ä»¶ã® RSC æå¹åãµãŒãã¹ãå ¬éãããŠãããè匱æ§ã®æ¡æ£ãªã¹ã¯ãéåžžã«é«ãããšã確èªãããŸããããããé©çšãšäœµããŠãå ¬éããã RSC ãµãŒãã¹ã®æ€åºããªã¢ã«ã¿ã€ã ç£èŠã¯ React2Shell 察çã®äžå¿ãšãªãèŠçŽ ã§ãããCriminal IP ã¯ããããæ»æå¯Ÿè±¡é åãæ£ç¢ºã«ææ¡ããé²åŸ¡ããããã®æå¹ãªææ®µãšãªããŸãã
ãªããé¢é£ããŠNext.js Middlewareã®èªèšŒãã€ãã¹èåŒ±æ§ ïŒ52äžä»¶ä»¥äžã®Webè³ç£ãå±éºã«ããããã ã®èšäºããåç §ãã ããã
æ¬ã¬ããŒãã¯ããµã€ããŒè
åšã€ã³ããªãžã§ã³ã¹æ€çŽ¢ãšã³ãžã³Â Criminal IP ã®ããŒã¿ãåºã«äœæãããŠããŸãã
ä»ããCriminal IP ã®ç¡æã¢ã«ãŠã³ããäœæããã°ãæ¬ã¬ããŒãã§åŒçšãããæ€çŽ¢çµæãçŽæ¥ç¢ºèªããããããã«èšå€§ãªè
åšã€ã³ããªãžã§ã³ã¹ãèªç±ã«æ€çŽ¢ããããšãã§ããŸããÂ
ããŒã¿ãœãŒã¹ : Criminal IP (https://www.criminalip.io/ja), CISA (https://www.cisa.gov/news-events/alerts/2025/12/05/cisa-adds-one-known-exploited-vulnerability-catalog), The Hacker News (https://thehackernews.com/2025/12/critical-react2shell-flaw-added-to-cisa.html)
é¢é£èšäº : https://www.criminalip.io/ja/knowledge-hub/blog/5528
