RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers Emmie Evans January 1, 2026

RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers

Cybersecurity researchers have disclosed details of a persistent nine-month-long campaign that has targeted Internet of Things (IoT) devices and web applications to enroll them into a botnet known as RondoDox.
As of December 2025, the activity has been observed leveraging the recently disclosed React2Shell (CVE-2025-55182, CVSS score: 10.0) flaw as an initial access vector, CloudSEK said in an

Write a comment
Your email address will not be published. Required fields are marked *
Scroll to Top