CVE-2026-19891
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-19891, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-15

Assigner: VulDB

Description

A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This affects an unknown function of the file /etc/racoon.conf of the component IKE Phase 1 Aggressive Mode. This manipulation of the argument exchange_mode causes missing encryption of sensitive data. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The vendor was contacted early about this disclosure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-15
Generated
2026-08-15
AI Q&A
2026-08-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trendnet tew-wlc100 2.05b02

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-311 The product does not encrypt sensitive or critical information before storage or transmission.
CWE-310 Cryptographic Issues

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects TRENDnet TEW-WLC100 version 2.05b02, specifically in the IKE Phase 1 Aggressive Mode. It involves a missing encryption of sensitive data due to manipulation of the exchange_mode argument in the /etc/racoon.conf file. The attack can be initiated remotely but requires high complexity and is difficult to exploit.

Impact Analysis

The vulnerability could allow an attacker to intercept and read sensitive data transmitted during IKE Phase 1 Aggressive Mode negotiations. This may lead to exposure of confidential information, though the high attack complexity and difficulty reduce the risk of exploitation.

Mitigation Strategies

Update the TRENDnet TEW-WLC100 device to the latest firmware version to address the vulnerability in the IKE Phase 1 Aggressive Mode configuration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19891. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart