CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ceragon 1Fibeair Ip 10 Firmware May 13, 2026 Jun 1, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key. |
1Ceragon 1Fibeair Ip 10 Firmware May 13, 2026 Mar 30, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALBATROSS cookie with the value 0-4-11 to their browser. |