Vulnerability Description
In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary attacks, and lacks flexibility in negotiating security parameters.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendnet | Tew-Wlc100P Firmware | 2.03b03 |
| Trendnet | Tew-Wlc100P | - |
Related Weaknesses (CWE)
References
- http://tew-wlc100p.comBroken Link
- https://gist.github.com/TPCchecker/6d787c4916891f493b274b70abfad860Broken Link
- https://www.notion.so/CVE-2025-44649-24754a1113e780a4a1d1c4cd6d3ff345
FAQ
What is CVE-2025-44649?
CVE-2025-44649 is a vulnerability with a CVSS score of 7.5 (HIGH). In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, ...
How severe is CVE-2025-44649?
CVE-2025-44649 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-44649?
Check the references section above for vendor advisories and patch information. Affected products include: Trendnet Tew-Wlc100P Firmware, Trendnet Tew-Wlc100P.