← Vulnerability feed

Vulnerability record · CVE-2016-6603 · published 23 January 2017

CVE-2016-6603: ZOHO WebNMS Framework authentication bypass via UserName header

Zohocorp · Webnms Framework

ZOHO WebNMS Framework 5.2 and 5.2 SP1 trusts the UserName HTTP header for identity, allowing remote attackers to bypass authentication and impersonate arbitrary users. Because the flaw is reachable over the network without credentials, it exposes the management platform to full compromise.

9.8 CVSS 3.0 Critical EPSS 87% · top 0.3% CWE-20 · Improper input validation
9.8CVSS 3.0 base score, v2 5.0
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit code available and very high EPSS probability make this an urgent exposure for any internet- or broadly reachable WebNMS 5.2 deployment.

What it is

ZOHO WebNMS Framework 5.2 and 5.2 SP1 trusts the UserName HTTP header for identity, allowing remote attackers to bypass authentication and impersonate arbitrary users. Because the flaw is reachable over the network without credentials, it exposes the management platform to full compromise.

Impact

An attacker gains the privileges of any impersonated user, including administrative access to the WebNMS management server. This enables configuration changes, data access and further lateral movement within the managed environment.

Attack surface

Reachable over the network via HTTP requests to the WebNMS web interface; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Public exploit code and technical descriptions are referenced (Exploit-DB, Packet Storm, Full Disclosure, SecuriTeam), and EPSS is 0.8704 (99.7th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.

What to do

  • Apply the vendor fix or upgrade WebNMS Framework beyond 5.2 SP1 as advised by ZOHO.
  • If patching is not possible, restrict network access to the WebNMS web interface to trusted management networks only.
  • Place the WebNMS server behind an authenticating reverse proxy or VPN so unauthenticated requests cannot reach it.
  • Remove or override any reliance on client-supplied UserName headers at the application or proxy layer.
  • Monitor vendor forums and advisories for updated guidance specific to WebNMS 5.2.

Detection

  • Inspect HTTP request logs for UserName headers that do not match the authenticated session or source identity.
  • Alert on requests to WebNMS endpoints from unexpected source IPs or without prior authentication steps.
  • Correlate WebNMS access logs with authentication logs to find sessions that never completed a login.
  • Hunt for known exploit payload patterns from the public PoC references against WebNMS URLs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/138244/WebNMS-Framework-5.2-SP1-Traversal-Weak-Obfuscation-User-Impersonation.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2016/Aug/54 ExploitMailing ListThird Party Advisory
http://www.securityfocus.com/archive/1/539159/100/0/threaded
http://www.securityfocus.com/bid/92402 Third Party AdvisoryVDB Entry
https://blogs.securiteam.com/index.php/archives/2712 ExploitTechnical DescriptionThird Party Advisory
https://forums.webnms.com/topic/recent-vulnerabilities-in-webnms-and-how-to-protect-the-server-against-them
https://github.com/pedrib/PoC/blob/master/advisories/webnms-5.2-sp1-pwn.txt ExploitThird Party Advisory
https://www.exploit-db.com/exploits/40229/ ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/138244/WebNMS-Framework-5.2-SP1-Traversal-Weak-Obfuscation-User-Impersonation.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2016/Aug/54 ExploitMailing ListThird Party Advisory
http://www.securityfocus.com/archive/1/539159/100/0/threaded
http://www.securityfocus.com/bid/92402 Third Party AdvisoryVDB Entry
https://blogs.securiteam.com/index.php/archives/2712 ExploitTechnical DescriptionThird Party Advisory
https://forums.webnms.com/topic/recent-vulnerabilities-in-webnms-and-how-to-protect-the-server-against-them
https://github.com/pedrib/PoC/blob/master/advisories/webnms-5.2-sp1-pwn.txt ExploitThird Party Advisory
https://www.exploit-db.com/exploits/40229/ ExploitThird Party AdvisoryVDB Entry

Track CVE-2016-6603 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-6600ZOHO WebNMS Framework file upload path traversal allows JSP executionZOHO WebNMS Framework 5.2 and 5.2 SP1 contain a directory traversal flaw in the file upload servlet (servlets/FileUploadServlet). The fileName parame…EPSS 91%analysed9.8CVE-2016-6602ZOHO WebNMS Framework weak password obfuscation exposes cleartext credentialsZOHO WebNMS Framework 5.2 and 5.2 SP1 store passwords using a weak obfuscation algorithm rather than proper hashing. Anyone who can read WEB-INF/conf…EPSS 55%analysed7.5CVE-2016-6601ZOHO WebNMS Framework FetchFile path traversal allows arbitrary file readThe file download servlet servlets/FetchFile in ZOHO WebNMS Framework 5.2 and 5.2 SP1 fails to sanitize the fileName parameter, allowing directory tr…EPSS 97%analysed9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 0.90%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed10.0CVE-2026-34910Ubiquiti UniFi OS input validation flaw allows command injectionUniFi OS devices contain an improper input validation vulnerability (CWE-20) that lets a network-reachable attacker inject and execute commands. It a…KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2016-6603), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.