CVE-2016-6601 is a directory traversal vulnerability in ZOHO WebNMS Framework versions 5.2 and 5.2 SP1, allowing remote attackers to read arbitrary files. This high-severity flaw (CVSS 7.5) has a low attack complexity and requires no authentication, enabling attackers to access sensitive information. While not listed in CISA KEV, exploit code is publicly available via Metasploit modules, Nuclei templates, and ExploitDB, indicating a high likelihood of exploitation. Community discussion and a high EPSS score further emphasize its potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2CPE matchmatch criteria | cpe:2.3:a:zohocorp:webnms_framework:5.2:*:*:*:*:*:*:* | ||
5.2CPE matchmatch criteria | cpe:2.3:a:zohocorp:webnms_framework:5.2:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.