CVE-2013-3610
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
05/10/2013
Last modified:
11/04/2025
Description
qis/QIS_finish.htm on the ASUS RT-N10E router with firmware before 2.0.0.25 does not require authentication, which allows remote attackers to discover the administrator password via a direct request.
Impact
Base Score 2.0
6.10
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:asus:rt-n10e_firmware:*:*:*:*:*:*:*:* | 2.0.0.24 (including) | |
cpe:2.3:o:asus:rt-n10e_firmware:2.0.0.7:*:*:*:*:*:*:* | ||
cpe:2.3:o:asus:rt-n10e_firmware:2.0.0.10:*:*:*:*:*:*:* | ||
cpe:2.3:o:asus:rt-n10e_firmware:2.0.0.16:*:*:*:*:*:*:* | ||
cpe:2.3:o:asus:rt-n10e_firmware:2.0.0.19:*:*:*:*:*:*:* | ||
cpe:2.3:o:asus:rt-n10e_firmware:2.0.0.20:*:*:*:*:*:*:* | ||
cpe:2.3:h:asus:rt-n10e:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page