---
id: CVE-2025-6225
title: Kieback&Peter Neutrino-GLT product is used for building management
summary: "Kieback&Peter Neutrino-GLT product is used for building management. It's web component\_\"SM70 PHWEB\" is vulnerable to shell command injection via login form. The injected commands would execute with low privileges. The vulnerability has b…"
severity: none
cwe:
  - CWE-78
published: '2026-01-07'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6225'
references:
  - url: 'https://cert.pl/en/posts/2026/01/CVE-2025-6225/'
    label: cvd@cert.pl
tags:
  - nvd
epss: 0.01098
epssPercentile: 0.64361
ingestedAt: '2026-09-30T22:27:27.732Z'
---

## Overview

Kieback&Peter Neutrino-GLT product is used for building management. It's web component "SM70 PHWEB" is vulnerable to shell command injection via login form. The injected commands would execute with low privileges. The vulnerability has been fixed in version 9.40.02

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
