In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the strongSwan configuration file, so that IKE Responders are allowed to use IKEv1 Aggressive Mode with Pre-Shared Keys to conduct offline attacks on the openly transmitted hash of the PSK.
The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.
Link | Tags |
---|---|
http://tew-wlc100p.com | broken link |
https://gist.github.com/TPCchecker/18c32439ed13feaed99f8229d1749892 | broken link |
https://www.notion.so/CVE-2025-44647-24754a1113e780b0a130d4439861bf3c | third party advisory |