PT-2026-1655 · Kieback & Peter · Sm70 Phweb+1

·

CVE-2025-6225

·

Published

2026-01-07

·

Updated

2026-01-07

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Kieback&Peter Neutrino-GLT versions prior to 9.40.02
Description The web component "SM70 PHWEB" of the Kieback&Peter Neutrino-GLT product, used for building management, contains a shell command injection flaw through the login form. Successful exploitation allows execution of commands with low privileges.
Recommendations Update to version 9.40.02 or later.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-6225

Affected Products

Neutrino-Glt
Sm70 Phweb