Executive brief
A security vulnerability exists in the TRENDnet TEW-WLC100P wireless controller, a device used to manage corporate Wi-Fi networks. The device's VPN configuration uses an insecure communication mode that transmits identity information without encryption. This could allow an unauthorized person to capture sensitive credentials and perform offline attacks to gain access to the network.
Technical details
The TRENDnet TEW-WLC100P (firmware 2.03b03) utilizes the 'racoon' IKE daemon with an insecure default configuration. Specifically, the 'exchange_mode' for IKE Phase 1 is set to 'aggressive' rather than 'main' mode. This configuration flaw results in the transmission of hashed authentication data and identity information in cleartext over the network. A remote, unauthenticated attacker can capture this traffic to perform offline dictionary or brute-force attacks against the Pre-Shared Key (PSK) and identify connecting users. This is classified as cleartext storage/transmission of sensitive information (CWE-312).
Affected products
- TRENDnet TEW-WLC100P firmware 2.03b03
Timeline
- 2025-07-21: disclosed
- 2025-07-21: advisory