CVE-2026-9033
Awaiting Analysis Awaiting Analysis - Queue

Session Termination Vulnerability in Captive Portal Service

Vulnerability report for CVE-2026-9033, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-09-08

Assigner: TPLink

Description

An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access.Β  Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-09-08
Generated
2026-09-10
AI Q&A
2026-08-20
EPSS Evaluated
2026-09-09
NVD
EUVD

Affected Vendors & Products

Showing 19 associated CPEs
Vendor Product Version / Range
tp-link er7212pc_firmware to 2.4.3 (exc)
tp-link er605_firmware to 2.4.4 (exc)
tp-link er7206_firmware to 2.3.5 (exc)
tp-link er7406_firmware to 1.3.4 (exc)
tp-link er707-m2_firmware to 1.4.4 (exc)
tp-link er7412-m2_firmware to 1.2.0 (exc)
tp-link er8411_firmware to 1.4.1 (exc)
tp-link er706w_firmware to 1.2.11 (exc)
tp-link er706w-4g_firmware to 1.2.6 (exc)
tp-link er706w-4g_firmware to 2.1.11 (exc)
tp-link er706wp-4g_firmware to 1.1.11 (exc)
tp-link er703wp-4g-outdoor_firmware to 1.1.7 (exc)
tp-link dr3220v-4g_firmware to 1.2.0 (exc)
tp-link dr3650v_firmware to 1.2.0 (exc)
tp-link dr3650v-4g_firmware to 1.2.0 (exc)
tp-link er603wp-4g-outdoor_firmware to 1.0.2 (exc)
tp-link dr3150_firmware to 1.0.1 (exc)
tp-link er701-5g-outdoor_firmware to 1.0.3 (exc)
tp-link er605w_firmware to 2.0.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated attacker on the same network to forcibly log out users from the captive portal service of affected devices. It can terminate individual or all active sessions, requiring users to re-authenticate to regain access.

Detection Guidance

This vulnerability cannot be directly detected through commands as it involves unauthorized session termination via the captive portal service. Monitor for unexpected user logouts or session resets in Omada Gateway logs. Check for firmware updates from TP-Link to patch the issue.

Impact Analysis

Exploitation may cause temporary service disruption by forcing users to re-authenticate. This could lead to inconvenience, loss of connectivity, or potential denial of access to network resources until users log back in.

Compliance Impact

This vulnerability may impact compliance with GDPR and HIPAA by causing temporary service disruption and unauthorized session termination, potentially leading to unauthorized access or data exposure during re-authentication. Affected users must re-authenticate, which could introduce risks of session hijacking or unauthorized data access if not properly mitigated.

Mitigation Strategies

Update your TP-Link Omada Gateway devices to the latest firmware versions to address the vulnerability. Affected users should also monitor network traffic for unusual session termination attempts targeting the captive portal service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9033. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart