Ceragon develops wireless backhaul and microwave transmission products, with vulnerabilities concentrated in its FibeAir IP line of point-to-point radio access equipment. The durable signal centers on authentication and credential-management weaknesses, including improper authentication validation, hard-coded credentials, and insecure default initialization, which are characteristic of remote management interfaces on network infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ceragon over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-0936CRITICAL Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH access by leveraging knowledge of | Jun 1, 2017 | 9.8 | 87 | NO | YES |
CVE-2016-10309CRITICAL In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALBATROSS cookie with the value 0-4-11 to their browser. | Mar 30, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-9137HIGH Ceragon FibeAir IP-10 wireless radios through 7.2.0 have a default password of mateidu for the mateidu account (a hidden user account established by the vendor). This account can b | May 21, 2017 | 7.3 | 24 | NO | NO |
CVE-2025-57175MEDIUM Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password. | Apr 8, 2026 | 6.8 | 23 | NO | NO |
CVE-2015-0924HIGH Ceragon FibeAir IP-10 bridges have a default password for the root account, which makes it easier for remote attackers to obtain access via a (1) HTTP, (2) SSH, (3) TELNET, or (4) | Jan 17, 2015 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ceragon.
Media articles that mention a CVE ID that affects a product developed by Ceragon — matched by CVE ID, not by vendor name.