CVE-2026-9033 Details
Description
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access. Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.omadanetworks.com/en/support/download/ | TPLink | Product |
| https://www.omadanetworks.com/us/support/download/ | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5256/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link er7212pc firmware | < 2.4.3 |
CPE
Remediation
| |
| tp-link er7212pc | 2.0 |
CPE
Remediation
| |
| tp-link er605 firmware | < 2.4.4 |
CPE
Remediation
| |
| tp-link er605 | 2.0 |
CPE
Remediation
| |
| tp-link er7206 firmware | < 2.3.5 |
CPE
Remediation
| |
| tp-link er7206 | 2.0 |
CPE
Remediation
| |
| tp-link er7406 firmware | < 1.3.4 |
CPE
Remediation
| |
| tp-link er7406 | All versions |
CPE
Remediation
| |
| tp-link er707-m2 firmware | < 1.4.4 |
CPE
Remediation
| |
| tp-link er707-m2 | All versions |
CPE
Remediation
| |
| tp-link er7412-m2 firmware | < 1.2.0 |
CPE
Remediation
| |
| tp-link er7412-m2 | All versions |
CPE
Remediation
| |
| tp-link er8411 firmware | < 1.4.1 |
CPE
Remediation
| |
| tp-link er8411 | All versions |
CPE
Remediation
| |
| tp-link er706w firmware | < 1.2.11 |
CPE
Remediation
| |
| tp-link er706w | All versions |
CPE
Remediation
| |
| tp-link er706w-4g firmware | < 1.2.6 < 2.1.11 |
CPE
Remediation
| |
| tp-link er706w-4g | 2.0 |
CPE
Remediation
| |
| tp-link er706wp-4g firmware | < 1.1.11 |
CPE
Remediation
| |
| tp-link er706wp-4g | All versions |
CPE
Remediation
| |
| tp-link er703wp-4g-outdoor firmware | < 1.1.7 |
CPE
Remediation
| |
| tp-link er703wp-4g-outdoor | All versions |
CPE
Remediation
| |
| tp-link dr3220v-4g firmware | < 1.2.0 |
CPE
Remediation
| |
| tp-link dr3220v-4g | All versions |
CPE
Remediation
| |
| tp-link dr3650v firmware | < 1.2.0 |
CPE
Remediation
| |
| tp-link dr3650v | All versions |
CPE
Remediation
| |
| tp-link dr3650v-4g firmware | < 1.2.0 |
CPE
Remediation
| |
| tp-link dr3650v-4g | All versions |
CPE
Remediation
| |
| tp-link er603wp-4g-outdoor firmware | < 1.0.2 |
CPE
Remediation
| |
| tp-link er603wp-4g-outdoor | All versions |
CPE
Remediation
| |
| tp-link dr3150 firmware | < 1.0.1 |
CPE
Remediation
| |
| tp-link dr3150 | All versions |
CPE
Remediation
| |
| tp-link er701-5g-outdoor firmware | < 1.0.3 |
CPE
Remediation
| |
| tp-link er701-5g-outdoor | All versions |
CPE
Remediation
| |
| tp-link er605w firmware | < 2.0.4 |
CPE
Remediation
| |
| tp-link er605w | 2.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | Initial Analysis | [email protected] |
| Aug 20, 2026 | New CVE Received | TPLink |
| Aug 20, 2026 | CVE Modified | CISA-ADP |