Vulnerability record · CVE-2016-6603 · published 23 January 2017
CVE-2016-6603: ZOHO WebNMS Framework authentication bypass via UserName header
Zohocorp · Webnms Framework
ZOHO WebNMS Framework 5.2 and 5.2 SP1 trusts the UserName HTTP header for identity, allowing remote attackers to bypass authentication and impersonate arbitrary users. Because the flaw is reachable over the network without credentials, it exposes the management platform to full compromise.
Description
ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit code available and very high EPSS probability make this an urgent exposure for any internet- or broadly reachable WebNMS 5.2 deployment.
What it is
ZOHO WebNMS Framework 5.2 and 5.2 SP1 trusts the UserName HTTP header for identity, allowing remote attackers to bypass authentication and impersonate arbitrary users. Because the flaw is reachable over the network without credentials, it exposes the management platform to full compromise.
Impact
An attacker gains the privileges of any impersonated user, including administrative access to the WebNMS management server. This enables configuration changes, data access and further lateral movement within the managed environment.
Attack surface
Reachable over the network via HTTP requests to the WebNMS web interface; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Public exploit code and technical descriptions are referenced (Exploit-DB, Packet Storm, Full Disclosure, SecuriTeam), and EPSS is 0.8704 (99.7th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.
What to do
- Apply the vendor fix or upgrade WebNMS Framework beyond 5.2 SP1 as advised by ZOHO.
- If patching is not possible, restrict network access to the WebNMS web interface to trusted management networks only.
- Place the WebNMS server behind an authenticating reverse proxy or VPN so unauthenticated requests cannot reach it.
- Remove or override any reliance on client-supplied UserName headers at the application or proxy layer.
- Monitor vendor forums and advisories for updated guidance specific to WebNMS 5.2.
Detection
- Inspect HTTP request logs for UserName headers that do not match the authenticated session or source identity.
- Alert on requests to WebNMS endpoints from unexpected source IPs or without prior authentication steps.
- Correlate WebNMS access logs with authentication logs to find sessions that never completed a login.
- Hunt for known exploit payload patterns from the public PoC references against WebNMS URLs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-6603 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-6603), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.