Vulnerability record · CVE-2016-6601 · published 23 January 2017
CVE-2016-6601: ZOHO WebNMS Framework FetchFile path traversal allows arbitrary file read
Zohocorp · Webnms Framework
The file download servlet servlets/FetchFile in ZOHO WebNMS Framework 5.2 and 5.2 SP1 fails to sanitize the fileName parameter, allowing directory traversal with .. sequences. A remote unauthenticated attacker can read arbitrary files from the server filesystem, which can expose credentials and configuration data.
Description
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote arbitrary file read with public exploit code and very high EPSS, though not in KEV and limited to confidentiality impact.
What it is
The file download servlet servlets/FetchFile in ZOHO WebNMS Framework 5.2 and 5.2 SP1 fails to sanitize the fileName parameter, allowing directory traversal with .. sequences. A remote unauthenticated attacker can read arbitrary files from the server filesystem, which can expose credentials and configuration data.
Impact
An attacker gains read access to any file the WebNMS process can reach, including configuration and credential files, enabling further compromise such as user impersonation. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network via HTTP requests to servlets/FetchFile with a crafted fileName parameter. The CVSS vector shows no privileges or user interaction required, so it is unauthenticated and remotely triggerable.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.974, 99.9th percentile) and multiple references are tagged Exploit, including Exploit-DB 40229 and public PoC and Metasploit modules, indicating mature public exploitation.
What to do
- Upgrade or patch WebNMS Framework beyond 5.2 SP1 per vendor guidance; if no fix is available, isolate or retire the affected deployment.
- Restrict network access to the WebNMS web interface and servlets/FetchFile to trusted management networks only.
- Run the WebNMS service with least privilege and limit filesystem read permissions so traversal yields minimal data.
- Review the vendor forum advisory on recent WebNMS vulnerabilities and apply any recommended hardening.
- Monitor and block traversal patterns such as .. in request parameters at a reverse proxy or WAF.
Detection
- Search web and proxy logs for requests to servlets/FetchFile containing .. or encoded traversal sequences in the fileName parameter.
- Alert on FetchFile requests returning unusually large responses or files outside expected download paths.
- Monitor for access to sensitive files such as configuration or credential stores by the WebNMS process.
- Correlate FetchFile requests with subsequent authentication or impersonation activity against WebNMS.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-6601 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-6601), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.