CVE-2025-44649: High severity Trendnet TEW-WLC100P vulnerability
In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchagemode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary attacks, and lacks flexibility in negotiating security parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In the racoon configuration file on TRENDnet TEW-WLC100P version 2.03b03, change the first item of exchage_mode from aggressive to a non-aggressive mode to prevent plaintext identity exposure and offline dictionary attacks.
racoon (TRENDnet TEW-WLC100P) exchange_mode (first item) = aggressive -> (set to non-aggressive)
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44649?
CVE-2025-44649 is classified as a high severity vulnerability due to its exposure of identity information and susceptibility to offline dictionary attacks.
How do I fix CVE-2025-44649?
To fix CVE-2025-44649, update the configuration file of racoon on the TRENDnet TEW-WLC100P to use main mode instead of aggressive mode.
What systems are affected by CVE-2025-44649?
CVE-2025-44649 affects the TRENDnet TEW-WLC100P running version 2.03b03.
What risks are associated with CVE-2025-44649?
The risks associated with CVE-2025-44649 include potential identity exposure in plaintext and increased vulnerability to unauthorized access through dictionary attacks.
Is there a workaround for CVE-2025-44649?
A workaround for CVE-2025-44649 is to disable aggressive mode in the configuration file until a patch is applied.