CVE-2025-44649: TRENDnet Tew-WLC100P Firmware

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary attacks, and lacks flexibility in negotiating security parameters.

Affected products

  • TRENDnet Tew-WLC100P Firmware: version 2.03b03 only

Published 2025-07-21. Last modified 2026-07-05.