Description
A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This affects an unknown function of the file /etc/racoon.conf of the component IKE Phase 1 Aggressive Mode. This manipulation of the argument exchange_mode causes missing encryption of sensitive data. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The vendor was contacted early about this disclosure.
Published: 2026-08-15
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in TRENDnet TEW‑WLC100 firmware version 2.05b02 allows an attacker to manipulate the exchange_mode setting in /etc/racoon.conf, causing the IKE Phase 1 aggressive mode to operate without encryption. This leads to the transmission of sensitive data in clear text. The vulnerability is exploitable remotely, but the attack requires nontrivial skills to configure the remote host and modify the configuration file, and the reported exploitability is classified as difficult. This is an example of improper handling of cryptographic parameters (CWE‑310) and weak cryptographic enforcement (CWE‑311).

Affected Systems

This issue affects TRENDnet TEW‑WLC100 wireless network controllers running firmware 2.05b02. The problem originates in the device’s racoon.conf configuration used by the IKE Phase 1 aggressive mode. No other TRENDnet products or versions are currently reported to be impacted.

Risk and Exploitability

The CVSS score of 6.3 reflects a moderate risk; EPSS data is not available, so the likelihood of widespread exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed active exploits. Successful exploitation would require remote access to the device that can read or modify the racoon.conf file, possibly via a web interface or management protocol, and the ability to enforce the modified exchange_mode setting. Once accomplished, the attacker could capture unencrypted VPN traffic and compromise confidentiality of exchanged data.

Generated by OpenCVE AI on August 15, 2026 at 16:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an updated firmware image that patches racoon.conf to enforce encryption in IKE Phase 1 aggressive mode.
  • If a firmware update is unavailable, modify /etc/racoon.conf to disable aggressive mode or enforce the correct exchange_mode setting and ensure the file is write‑protected and only accessible by trusted administrators.
  • Validate that the IKE configuration requires encryption and monitor system logs for any attempts to alter racoon.conf or initiate unencrypted IKE exchanges.

Generated by OpenCVE AI on August 15, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This affects an unknown function of the file /etc/racoon.conf of the component IKE Phase 1 Aggressive Mode. This manipulation of the argument exchange_mode causes missing encryption of sensitive data. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The vendor was contacted early about this disclosure.
Title TRENDnet TEW-WLC100 IKE Phase 1 Aggressive Mode racoon.conf missing encryption
First Time appeared Trendnet
Trendnet tew-wlc100
Weaknesses CWE-310
CWE-311
CPEs cpe:2.3:a:trendnet:tew-wlc100:*:*:*:*:*:*:*:*
Vendors & Products Trendnet
Trendnet tew-wlc100
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Trendnet Tew-wlc100
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-17T15:51:00.431Z

Reserved: 2026-08-14T18:41:58.487Z

Link: CVE-2026-19891

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-15T11:16:26.340

Modified: 2026-08-20T12:48:10.287

Link: CVE-2026-19891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-16T11:00:05Z

Weaknesses