FON2601E-SE, FON2601E-RE, FON2601E-FSW-S, and FON2601E-FSW-B with firmware versions 1.1.7 and earlier contain an issue where they may behave as open resolvers. If this vulnerability is exploited, FON routers may be leveraged for DNS amplification attacks to some other entities.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://fonjapan.zendesk.com/hc/ja/articles/360000558942 | third party advisory |
http://jvn.jp/en/vu/JVNVU94678942/index.html | third party advisory |