← Vulnerability feed

Vulnerability record · CVE-2016-6601 · published 23 January 2017

CVE-2016-6601: ZOHO WebNMS Framework FetchFile path traversal allows arbitrary file read

Zohocorp · Webnms Framework

The file download servlet servlets/FetchFile in ZOHO WebNMS Framework 5.2 and 5.2 SP1 fails to sanitize the fileName parameter, allowing directory traversal with .. sequences. A remote unauthenticated attacker can read arbitrary files from the server filesystem, which can expose credentials and configuration data.

7.5 CVSS 3.0 High EPSS 97% · top 0.1% CWE-22 · Path traversal
7.5CVSS 3.0 base score, v2 5.0
97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityUnauthenticated remote arbitrary file read with public exploit code and very high EPSS, though not in KEV and limited to confidentiality impact.

What it is

The file download servlet servlets/FetchFile in ZOHO WebNMS Framework 5.2 and 5.2 SP1 fails to sanitize the fileName parameter, allowing directory traversal with .. sequences. A remote unauthenticated attacker can read arbitrary files from the server filesystem, which can expose credentials and configuration data.

Impact

An attacker gains read access to any file the WebNMS process can reach, including configuration and credential files, enabling further compromise such as user impersonation. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network via HTTP requests to servlets/FetchFile with a crafted fileName parameter. The CVSS vector shows no privileges or user interaction required, so it is unauthenticated and remotely triggerable.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.974, 99.9th percentile) and multiple references are tagged Exploit, including Exploit-DB 40229 and public PoC and Metasploit modules, indicating mature public exploitation.

What to do

  • Upgrade or patch WebNMS Framework beyond 5.2 SP1 per vendor guidance; if no fix is available, isolate or retire the affected deployment.
  • Restrict network access to the WebNMS web interface and servlets/FetchFile to trusted management networks only.
  • Run the WebNMS service with least privilege and limit filesystem read permissions so traversal yields minimal data.
  • Review the vendor forum advisory on recent WebNMS vulnerabilities and apply any recommended hardening.
  • Monitor and block traversal patterns such as .. in request parameters at a reverse proxy or WAF.

Detection

  • Search web and proxy logs for requests to servlets/FetchFile containing .. or encoded traversal sequences in the fileName parameter.
  • Alert on FetchFile requests returning unusually large responses or files outside expected download paths.
  • Monitor for access to sensitive files such as configuration or credential stores by the WebNMS process.
  • Correlate FetchFile requests with subsequent authentication or impersonation activity against WebNMS.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/138244/WebNMS-Framework-5.2-SP1-Traversal-Weak-Obfuscation-User-Impersonation.html ExploitThird Party Advisory
http://seclists.org/fulldisclosure/2016/Aug/54 ExploitMailing List
http://www.rapid7.com/db/modules/auxiliary/admin/http/webnms_cred_disclosure Third Party Advisory
http://www.rapid7.com/db/modules/auxiliary/admin/http/webnms_file_download Third Party Advisory
http://www.securityfocus.com/archive/1/539159/100/0/threaded
http://www.securityfocus.com/bid/92402 Third Party AdvisoryVDB Entry
https://blogs.securiteam.com/index.php/archives/2712 ExploitTechnical DescriptionThird Party Advisory
https://forums.webnms.com/topic/recent-vulnerabilities-in-webnms-and-how-to-protect-the-server-against-them
https://github.com/pedrib/PoC/blob/master/advisories/webnms-5.2-sp1-pwn.txt Exploit
https://www.exploit-db.com/exploits/40229/ ExploitThird Party Advisory
http://packetstormsecurity.com/files/138244/WebNMS-Framework-5.2-SP1-Traversal-Weak-Obfuscation-User-Impersonation.html ExploitThird Party Advisory
http://seclists.org/fulldisclosure/2016/Aug/54 ExploitMailing List
http://www.rapid7.com/db/modules/auxiliary/admin/http/webnms_cred_disclosure Third Party Advisory
http://www.rapid7.com/db/modules/auxiliary/admin/http/webnms_file_download Third Party Advisory
http://www.securityfocus.com/archive/1/539159/100/0/threaded
http://www.securityfocus.com/bid/92402 Third Party AdvisoryVDB Entry
https://blogs.securiteam.com/index.php/archives/2712 ExploitTechnical DescriptionThird Party Advisory
https://forums.webnms.com/topic/recent-vulnerabilities-in-webnms-and-how-to-protect-the-server-against-them
https://github.com/pedrib/PoC/blob/master/advisories/webnms-5.2-sp1-pwn.txt Exploit
https://www.exploit-db.com/exploits/40229/ ExploitThird Party Advisory

Track CVE-2016-6601 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-6600ZOHO WebNMS Framework file upload path traversal allows JSP executionZOHO WebNMS Framework 5.2 and 5.2 SP1 contain a directory traversal flaw in the file upload servlet (servlets/FileUploadServlet). The fileName parame…EPSS 91%analysed9.8CVE-2016-6602ZOHO WebNMS Framework weak password obfuscation exposes cleartext credentialsZOHO WebNMS Framework 5.2 and 5.2 SP1 store passwords using a weak obfuscation algorithm rather than proper hashing. Anyone who can read WEB-INF/conf…EPSS 55%analysed9.8CVE-2016-6603ZOHO WebNMS Framework authentication bypass via UserName headerZOHO WebNMS Framework 5.2 and 5.2 SP1 trusts the UserName HTTP header for identity, allowing remote attackers to bypass authentication and impersonat…EPSS 87%analysed9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed

Source: NIST National Vulnerability Database (record CVE-2016-6601), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.