6.1

CVE-2013-3610

qis/QIS_finish.htm on the ASUS RT-N10E router with firmware before 2.0.0.25 does not require authentication, which allows remote attackers to discover the administrator password via a direct request.

Data is provided by the National Vulnerability Database (NVD)
AsusRt-n10e Firmware Version <= 2.0.0.24
AsusRt-n10e Firmware Version2.0.0.7
AsusRt-n10e Firmware Version2.0.0.10
AsusRt-n10e Firmware Version2.0.0.16
AsusRt-n10e Firmware Version2.0.0.19
AsusRt-n10e Firmware Version2.0.0.20
AsusRt-n10e Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.15% 0.368
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 6.5 6.9
AV:A/AC:L/Au:N/C:C/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.