ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a remote exploit.
Use CWE-327, Zohocorp vendor hub and Webnms Framework product page to widen CVE-2016-6602 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2016-6603, CVE-2016-6600 and CVE-2016-6601 for nearby disclosures in the same product family. Additional editorial context is available in Cybersecurity Weekly Roundup: April 27, 2026 — Critical Zero-Days and Framework Failures.