CVE-2016-6603: Zohocorp Webnms Framework

Critical severity, CVSS 9.8. EPSS: 86.9% chance of exploitation in the next 30 days.

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

Affected products

  • Zohocorp Webnms Framework: version 5.2 only

Published 2017-01-23. Last modified 2026-06-17.