Vulnerability record · CVE-2016-6602 · published 23 January 2017
CVE-2016-6602: ZOHO WebNMS Framework weak password obfuscation exposes cleartext credentials
Zohocorp · Webnms Framework
ZOHO WebNMS Framework 5.2 and 5.2 SP1 store passwords using a weak obfuscation algorithm rather than proper hashing. Anyone who can read WEB-INF/conf/securitydbData.xml can recover cleartext passwords, and the record notes this can be chained with CVE-2016-6601 for a remote exploit.
Description
ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a remote exploit.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no privileges or interaction required, public exploit code, and very high EPSS make credential compromise likely and severe.
What it is
ZOHO WebNMS Framework 5.2 and 5.2 SP1 store passwords using a weak obfuscation algorithm rather than proper hashing. Anyone who can read WEB-INF/conf/securitydbData.xml can recover cleartext passwords, and the record notes this can be chained with CVE-2016-6601 for a remote exploit.
Impact
An attacker who obtains the securitydbData.xml file recovers cleartext credentials, enabling account takeover and, per the record, remote exploitation when combined with CVE-2016-6601.
Attack surface
The flaw is reached by gaining access to the WEB-INF/conf/securitydbData.xml file, typically via a path traversal or file disclosure issue rather than direct network exposure. The CVSS vector (AV:N/AC:L/PR:N/UI:N) rates it as remotely reachable with no authentication or user interaction, though the description itself does not specify the exact retrieval path.
Exploitation
Public exploit code exists, including Exploit-DB 40229, a Rapid7 Metasploit module, and multiple advisory write-ups; the CVE is not listed in CISA KEV, while EPSS is 0.5507 (98.98th percentile), indicating high predicted exploitation activity.
What to do
- Upgrade or patch WebNMS Framework beyond 5.2 SP1 per vendor guidance; the vendor forum post is the only remediation reference in the record.
- Restrict network and filesystem access to WEB-INF/conf/securitydbData.xml and the WebNMS web root.
- Rotate all WebNMS credentials, since stored passwords are recoverable in cleartext.
- Replace the weak obfuscation with a strong salted password hash if the application is retained.
- Monitor for and block path traversal attempts against the WebNMS web interface.
Detection
- Alert on HTTP requests containing traversal sequences targeting WEB-INF/conf/securitydbData.xml.
- Monitor file access to securitydbData.xml outside expected application processes.
- Hunt for authentication using recovered WebNMS accounts from unusual source IPs.
- Review logs for the Rapid7 webnms_cred_disclosure module or Exploit-DB 40229 request patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-6602 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-6602), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.