Security Flaw in TRENDnet TEW-WLC100 Affects IKE Phase 1 Aggressive Mode
CVE-2026-19891

6.3MEDIUM

Key Information:

Vendor

Trendnet

Vendor
CVE Published:
15 August 2026

What is CVE-2026-19891?

A security flaw has been identified in the TRENDnet TEW-WLC100 version 2.05b02. This vulnerability resides within the IKE Phase 1 Aggressive Mode component, specifically affecting the /etc/racoon.conf file. An attacker can manipulate the argument exchange_mode, leading to sensitive data being transmitted without proper encryption. This misconfiguration can potentially allow remote exploitation, although the complexity of executing such an attack is considered to be high. The vendor was notified early in the disclosure process regarding this issue.

Affected Version(s)

TEW-WLC100 2.05b02

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

L14Utopia (VulDB User)
VulDB CNA Team
.