CVE-2016-6602: Zohocorp Webnms Framework

Critical severity, CVSS 9.8. EPSS: 55.7% chance of exploitation in the next 30 days.

ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a remote exploit.

Affected products

  • Zohocorp Webnms Framework: version 5.2 only

Published 2017-01-23. Last modified 2026-06-17.