| CVE ID | CVE-2025-6225 |
| Publication date | 07 January 2026 |
| Vendor | Kieback&Peter |
| Product | Neutrino-GLT |
| Vulnerable versions | All before 9.40.02 |
| Vulnerability type (CWE) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Kieback&Peter Neutrino-GLT product and participated in coordination of its disclosure.
Kieback&Peter Neutrino-GLT product is used for building management.
The vulnerability CVE-2025-6225: Kieback&Peter Neutrino-GLT's web component "SM70 PHWEB" is vulnerable to shell command injection via login form. The injected commands would execute with low system privileges.
The vulnerability has been fixed in version 9.40.02
Credits
We thank Jan Barszcz for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.