Loading
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.
Use CWE-22, Zohocorp vendor hub and Webnms Framework product page to widen CVE-2016-6601 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2016-6603, CVE-2016-6602 and CVE-2016-6600 for nearby disclosures in the same product family. Additional editorial context is available in Cybersecurity Weekly Roundup: April 27, 2026 — Critical Zero-Days and Framework Failures.