FibeAir IP-10 devices do not properly ensure that a user has authenticated before granting them access to the web interface of the device. The attacker simply needs to add a cookie to their session named "ALBATROSS" with the value "0-4-11".
ba7a5b7f1fb1761939ce81f563c29620f9f70fcbfab7ade4b67161271701849e