PT-2026-1655 · Kieback & Peter · Sm70 Phweb+1

Jan Barszcz

·

Published

2026-01-07

·

Updated

2026-01-07

·

CVE-2025-6225

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Kieback&Peter Neutrino-GLT versions prior to 9.40.02
Description The web component "SM70 PHWEB" of the Kieback&Peter Neutrino-GLT product, used for building management, contains a shell command injection flaw through the login form. Successful exploitation allows execution of commands with low privileges.
Recommendations Update to version 9.40.02 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-6225

Affected Products

Neutrino-Glt
Sm70 Phweb