CVE-2025-44649

In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary attacks, and lacks flexibility in negotiating security parameters.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:trendnet:tew-wlc100p_firmware:2.03b03:*:*:*:*:*:*:*
cpe:2.3:h:trendnet:tew-wlc100p:-:*:*:*:*:*:*:*

History

01 Aug 2025, 19:37

Type Values Removed Values Added
Summary
  • (es) En el archivo de configuración de racoon en el TRENDnet TEW-WLC100P 2.03b03, el primer elemento de exchage_mode está configurado como agresivo. El modo agresivo en la Fase 1 de IKE expone la información de identidad en texto plano, es vulnerable a ataques de diccionario sin conexión y carece de flexibilidad para negociar parámetros de seguridad.
References () http://tew-wlc100p.com - () http://tew-wlc100p.com - Broken Link
References () https://gist.github.com/TPCchecker/6d787c4916891f493b274b70abfad860 - () https://gist.github.com/TPCchecker/6d787c4916891f493b274b70abfad860 - Broken Link
First Time Trendnet tew-wlc100p Firmware
Trendnet tew-wlc100p
Trendnet
CPE cpe:2.3:h:trendnet:tew-wlc100p:-:*:*:*:*:*:*:*
cpe:2.3:o:trendnet:tew-wlc100p_firmware:2.03b03:*:*:*:*:*:*:*

22 Jul 2025, 14:15

Type Values Removed Values Added
CWE CWE-312
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

21 Jul 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 17:15

Updated : 2025-08-01 19:37


NVD link : CVE-2025-44649

Mitre link : CVE-2025-44649

CVE.ORG link : CVE-2025-44649


JSON object : View

Products Affected

trendnet

  • tew-wlc100p_firmware
  • tew-wlc100p
CWE
CWE-312

Cleartext Storage of Sensitive Information