@me@infosec.exchange Who are "some people"? :)
Attack Complexity (AC) measures actions taken by the attacker to actively circumvent existing built-in security-enhancing conditions.
What kind of circumvention and evasion must be fulfilled? As far as I see there aren't any.
Attack Requirements (AT) emerge naturally as a consequence of the deployment, not explicitly as an attack mitigation.
According to your argument, it's always AT: Present because every attack requires the attacker to use and setup a computer.
For the scoring to work, you have to assume the most powerful attacker possible, who of course has already set up a rouge password reset URL.
As I said, the only real requirement is the knowledge of an existing email address. With billions of leaked email addresses on the Internet, I am not sure this is a hard requirement to overcome.