In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALBATROSS cookie with the value 0-4-11 to their browser.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCeragon Fibeair Ip 10
HWCeragonall versionsCeragon Fibeair Ip 10 Firmware
OSCeragon≤ 7.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
Related vulnerabilities
CVE-2015-0936CRITICAL9.8PL ✓same product
Ceragon FibeAir IP-10 — domyślny klucz SSH umożliwia zdalny dostęp
CVE-2017-9137HIGH7.3same vendor
Ceragon FibeAir IP-10 wireless radios through 7.2.0 have a default password of mateidu for the mateidu account...
CVE-2015-0924HIGH7.8same vendor
Ceragon FibeAir IP-10 bridges have a default password for the root account, which makes it easier for remote a...
CVE-2025-57175MEDIUM6.4same vendor
Urządzenia Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b posiadają statyczne hasło root.