← Vulnerability feed

Vulnerability record · CVE-2016-6602 · published 23 January 2017

CVE-2016-6602: ZOHO WebNMS Framework weak password obfuscation exposes cleartext credentials

Zohocorp · Webnms Framework

ZOHO WebNMS Framework 5.2 and 5.2 SP1 store passwords using a weak obfuscation algorithm rather than proper hashing. Anyone who can read WEB-INF/conf/securitydbData.xml can recover cleartext passwords, and the record notes this can be chained with CVE-2016-6601 for a remote exploit.

9.8 CVSS 3.0 Critical EPSS 55% · top 1.0% CWE-327 · Broken cryptographic algorithm
9.8CVSS 3.0 base score, v2 5.0
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a remote exploit.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no privileges or interaction required, public exploit code, and very high EPSS make credential compromise likely and severe.

What it is

ZOHO WebNMS Framework 5.2 and 5.2 SP1 store passwords using a weak obfuscation algorithm rather than proper hashing. Anyone who can read WEB-INF/conf/securitydbData.xml can recover cleartext passwords, and the record notes this can be chained with CVE-2016-6601 for a remote exploit.

Impact

An attacker who obtains the securitydbData.xml file recovers cleartext credentials, enabling account takeover and, per the record, remote exploitation when combined with CVE-2016-6601.

Attack surface

The flaw is reached by gaining access to the WEB-INF/conf/securitydbData.xml file, typically via a path traversal or file disclosure issue rather than direct network exposure. The CVSS vector (AV:N/AC:L/PR:N/UI:N) rates it as remotely reachable with no authentication or user interaction, though the description itself does not specify the exact retrieval path.

Exploitation

Public exploit code exists, including Exploit-DB 40229, a Rapid7 Metasploit module, and multiple advisory write-ups; the CVE is not listed in CISA KEV, while EPSS is 0.5507 (98.98th percentile), indicating high predicted exploitation activity.

What to do

  • Upgrade or patch WebNMS Framework beyond 5.2 SP1 per vendor guidance; the vendor forum post is the only remediation reference in the record.
  • Restrict network and filesystem access to WEB-INF/conf/securitydbData.xml and the WebNMS web root.
  • Rotate all WebNMS credentials, since stored passwords are recoverable in cleartext.
  • Replace the weak obfuscation with a strong salted password hash if the application is retained.
  • Monitor for and block path traversal attempts against the WebNMS web interface.

Detection

  • Alert on HTTP requests containing traversal sequences targeting WEB-INF/conf/securitydbData.xml.
  • Monitor file access to securitydbData.xml outside expected application processes.
  • Hunt for authentication using recovered WebNMS accounts from unusual source IPs.
  • Review logs for the Rapid7 webnms_cred_disclosure module or Exploit-DB 40229 request patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/138244/WebNMS-Framework-5.2-SP1-Traversal-Weak-Obfuscation-User-Impersonation.html ExploitThird Party Advisory
http://seclists.org/fulldisclosure/2016/Aug/54 ExploitMailing List
http://www.rapid7.com/db/modules/auxiliary/admin/http/webnms_cred_disclosure Third Party Advisory
http://www.securityfocus.com/archive/1/539159/100/0/threaded
http://www.securityfocus.com/bid/92402 Third Party AdvisoryVDB Entry
https://blogs.securiteam.com/index.php/archives/2712 ExploitTechnical DescriptionThird Party Advisory
https://forums.webnms.com/topic/recent-vulnerabilities-in-webnms-and-how-to-protect-the-server-against-them
https://github.com/pedrib/PoC/blob/master/advisories/webnms-5.2-sp1-pwn.txt Exploit
https://www.exploit-db.com/exploits/40229/ ExploitThird Party Advisory
http://packetstormsecurity.com/files/138244/WebNMS-Framework-5.2-SP1-Traversal-Weak-Obfuscation-User-Impersonation.html ExploitThird Party Advisory
http://seclists.org/fulldisclosure/2016/Aug/54 ExploitMailing List
http://www.rapid7.com/db/modules/auxiliary/admin/http/webnms_cred_disclosure Third Party Advisory
http://www.securityfocus.com/archive/1/539159/100/0/threaded
http://www.securityfocus.com/bid/92402 Third Party AdvisoryVDB Entry
https://blogs.securiteam.com/index.php/archives/2712 ExploitTechnical DescriptionThird Party Advisory
https://forums.webnms.com/topic/recent-vulnerabilities-in-webnms-and-how-to-protect-the-server-against-them
https://github.com/pedrib/PoC/blob/master/advisories/webnms-5.2-sp1-pwn.txt Exploit
https://www.exploit-db.com/exploits/40229/ ExploitThird Party Advisory

Track CVE-2016-6602 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2016-6602), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.