CVE-2019-6015: Fon FON2601E-Fsw-B Firmware

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

FON2601E-SE, FON2601E-RE, FON2601E-FSW-S, and FON2601E-FSW-B with firmware versions 1.1.7 and earlier contain an issue where they may behave as open resolvers. If this vulnerability is exploited, FON routers may be leveraged for DNS amplification attacks to some other entities.

Affected products

  • Fon FON2601E-Fsw-B Firmware: up to and including 1.1.7
  • Fon FON2601E-Fsw-S Firmware: up to and including 1.1.7
  • Fon FON2601E-Re Firmware: up to and including 1.1.7
  • Fon FON2601E-SE Firmware: up to and including 1.1.7

Published 2019-10-04. Last modified 2026-06-17.