CVE-2016-10309: Ceragon Fibeair IP-10 Firmware
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALBATROSS cookie with the value 0-4-11 to their browser.
Affected products
- Ceragon Fibeair IP-10 Firmware: up to and including 7.1.0
Published 2017-03-30. Last modified 2026-06-17.