CVE-2025-44647: High severity Trendnet TEW-WLC100P vulnerability
In TRENDnet TEW-WLC100P 2.03b03, the idontcareaboutsecurityanduseaggressivemodepsk option is enabled in the strongSwan configuration file, so that IKE Responders are allowed to use IKEv1 Aggressive Mode with Pre-Shared Keys to conduct offline attacks on the openly transmitted hash of the PSK.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In TRENDnet TEW-WLC100P 2.03b03 strongSwan configuration, disable i_dont_care_about_security_and_use_aggressive_mode_psk so IKE Responders cannot use IKEv1 Aggressive Mode with PSKs for offline attacks.
strongSwan configuration (IKE settings) i_dont_care_about_security_and_use_aggressive_mode_psk = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44647?
CVE-2025-44647 has a high severity level due to its potential for offline attacks on Pre-Shared Keys.
How do I fix CVE-2025-44647?
To mitigate CVE-2025-44647, disable the aggressive mode option in the strongSwan configuration file.
What systems are affected by CVE-2025-44647?
CVE-2025-44647 affects the TRENDnet TEW-WLC100P when configured with strongSwan.
What are the potential impacts of CVE-2025-44647?
CVE-2025-44647 could allow attackers to conduct offline brute-force attacks on the Pre-Shared Keys.
Is CVE-2025-44647 related to IKEv1 configurations?
Yes, CVE-2025-44647 specifically involves the use of IKEv1 Aggressive Mode in its vulnerability.