Sceawere
Vulnerability Detail
CVE-2026-19891UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
TRENDnet TEW-WLC100 IKE Aggressive Mode Information Disclosure
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 3h ago
- Vendor
- TRENDnet
- Product
- TEW-WLC100
- Attack Type
- Missing Encryption of Sensitive Data
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This affects an unknown function of the file /etc/racoon.conf of the component IKE Phase 1 Aggressive Mode. This manipulation of the argument exchange_mode causes missing encryption of sensitive data. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The vendor was contacted early about this disclosure.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-08-15T11:16:26.340Z",
"pubdate": "2026-08-15T11:16:26.340Z",
"executiveSummary": "A vulnerability has been identified in the TRENDnet TEW-WLC100 wireless controller running firmware version 2.05b02, specifically within the Internet Key Exchange (IKE) Phase 1 Aggressive Mode implementation.\nThe flaw stems from improper configuration or handling of the exchange mode parameter within the /etc/racoon.conf configuration file, resulting in the transmission of sensitive cryptographic material or authentication data in cleartext or without adequate encryption.\nThis vulnerability allows remote attackers to intercept sensitive data exchanged during the negotiation phase, potentially leading to unauthorized information disclosure and facilitating subsequent cryptographic attacks.\nAlthough the attack can be initiated remotely, the overall exploitation complexity is assessed as rather high, and the practical exploitability is considered difficult due to the specific conditions required to capture and analyze the targeted network traffic.\nThe vendor was notified early regarding this security issue to facilitate remediation efforts.",
"technicalDetails": "The vulnerability resides in the Internet Key Exchange (IKE) Phase 1 component of the TRENDnet TEW-WLC100 device running version 2.05b02, specifically affecting the handling of the exchange mode configuration specified in the /etc/racoon.conf file.\nIKE Phase 1 is responsible for establishing a secure, authenticated communication channel (the ISAKMP SA) for IPsec VPNs. When configured or manipulated to utilize Aggressive Mode with improper parameter settings, the protocol can expose pre-shared key (PSK) hashes or identity information during the initial exchange.\nThe root cause is tied to missing encryption or weak confidentiality controls applied to sensitive parameters during the exchange_mode negotiation sequence. In standard implementations, Main Mode provides identity protection by deferring identity exchange until a secure channel is established, whereas Aggressive Mode transmits identities and cryptographic parameters in the initial messages, often unprotected depending on daemon configuration.\nThe attack flow requires an adversary positioned on the network path or capable of sniffing remote traffic destined for the vulnerable device's IKE endpoint (typically UDP port 500 or 4500).\nUpon initiation of an IKE session using the vulnerable exchange mode configuration, the device processes the request via the racoon daemon utilizing the parameters defined in /etc/racoon.conf.\nDue to the absence of required encryption or protection mechanisms for sensitive data elements within this specific execution path, the system transmits unencrypted or weakly protected sensitive payloads across the network.\nAn external attacker captures these initial negotiation packets remotely. Following successful interception, the adversary can perform offline cryptanalysis, such as brute-force or dictionary attacks against captured pre-shared key hashes, potentially compromising the underlying authentication credentials.\nNetwork exposure is remote, requiring network connectivity to the IPsec/IKE service exposed by the target device. No prior authentication or elevated privileges are strictly required to capture the initial handshake packets, as IKE negotiation is publicly accessible by design to establish connections.\nPost-exploitation impact includes the potential recovery of pre-shared keys, compromise of the IPsec VPN tunnel, and subsequent unauthorized access to internal network segments managed by the TRENDnet TEW-WLC100 controller."
}