CVE-2026-9033
Received Received - Intake

Session Termination Vulnerability in Captive Portal Service

Vulnerability report for CVE-2026-9033, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: TPLink

Description

An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access.Β  Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tp-link omada_gateway *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated attacker on the same network to forcibly log out users from the captive portal service of affected devices. It can terminate individual or all active sessions, requiring users to re-authenticate to regain access.

Impact Analysis

Exploitation may cause temporary service disruption by forcing users to re-authenticate. This could lead to inconvenience, loss of connectivity, or potential denial of access to network resources until users log back in.

Compliance Impact

This vulnerability may impact compliance with GDPR and HIPAA by causing temporary service disruption and unauthorized session termination, potentially leading to unauthorized access or data exposure during re-authentication. Affected users must re-authenticate, which could introduce risks of session hijacking or unauthorized data access if not properly mitigated.

Mitigation Strategies

Update your TP-Link Omada Gateway devices to the latest firmware versions to address the vulnerability. Affected users should also monitor network traffic for unusual session termination attempts targeting the captive portal service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9033. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart