CVE-2004-1685
Status: ModifiedHigh (7.5)—
SMC routers SMC7004VWBR running firmware 1.00.014 and SMC7008ABR EU running firmware 1.42.003 allow remote attackers to bypass authentication by connecting to it from the same IP address as the administrator who is logged in, then accessing the setup_status.htm or status.HTM pages.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.84%
- Percentile among all scored CVEs: 78
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- NVD-CWE-Other
References
- http://marc.info/?l=bugtraq&m=109526094614160&w=2
- http://secunia.com/advisories/12601
- http://www.osvdb.org/10088
- http://www.securityfocus.com/bid/11197
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17443
- http://marc.info/?l=bugtraq&m=109526094614160&w=2
- http://secunia.com/advisories/12601
- http://www.osvdb.org/10088
- http://www.securityfocus.com/bid/11197
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17443
Raw JSON (NVD)
Show
{
"id": "CVE-2004-1685",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2004-09-15T04:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=109526094614160&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/12601",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/10088",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/11197",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/17443",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=109526094614160&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/12601",
"tags": [
"Exploit",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/10088",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/11197",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/17443",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SMC routers SMC7004VWBR running firmware 1.00.014 and SMC7008ABR EU running firmware 1.42.003 allow remote attackers to bypass authentication by connecting to it from the same IP address as the administrator who is logged in, then accessing the setup_status.htm or status.HTM pages."
}
],
"lastModified": "2026-06-16T22:08:12.353",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:smc_networks:smc7004vwbr:1.21a:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C548507-4D36-4306-9F63-93CAC1B6922D"
},
{
"criteria": "cpe:2.3:h:smc_networks:smc7004vwbr:1.22:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DEB5C35-39F4-41A4-BDD3-634F1EE530A4"
},
{
"criteria": "cpe:2.3:h:smc_networks:smc7004vwbr:1.23:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8205F896-AE0D-451F-883C-4AC8116C66D6"
},
{
"criteria": "cpe:2.3:h:smc_networks:smc7008abr:1.32:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C227D3AD-A691-43AD-9587-CE4E19C7B2D6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}