Unauthenticated Captive Portal Session Termination and Forced Logout in Omada Gateways
Summary
| CVE | CVE-2026-9033 |
|---|---|
| State | PUBLISHED |
| Assigner | TPLink |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-20 19:17:04 UTC |
| Updated | 2026-08-20 19:17:04 UTC |
| Description | An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access. Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate. |
Risk And Classification
Primary CVSS: v4.0 6 MEDIUM from f23511db-6c3e-4e32-a477-6aa17d310630
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-306 | CWE-306 CWE-306 Missing Authentication for Critical Function
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | f23511db-6c3e-4e32-a477-6aa17d310630 | Secondary | 6 | MEDIUM | CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 6 | MEDIUM | CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
AdjacentAttack Complexity
LowAttack Requirements
PresentPrivileges Required
NoneUser Interaction
NoneConfidentiality
NoneIntegrity
NoneAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | TP-Link Systems Inc. | ER7212PC V2 | affected 2.4.3 Build 20260722 Rel.40250 custom | Not specified |
| CNA | TP-Link Systems Inc. | ER605 V2 | affected 2.4.4 Build 20260630 Rel.14398 custom | Not specified |
| CNA | TP-Link Systems Inc. | ER7206 V2 | affected 2.3.5 Build 20260625 Rel.43136 custom | Not specified |
| CNA | TP-Link Systems Inc | ER7406 V1 | affected 1.3.4 Build 20260625 Rel.43136 custom | Not specified |
| CNA | TP-Link Systems Inc. | ER707-M2 V1 | affected 1.4.4 Build 20260625 Rel.43063 custom | Not specified |
| CNA | TP-Link Systems Inc | ER7412-M2 V1 | affected 1.2.0 Build 20260630 Rel.82947 custom | Not specified |
| CNA | TP-Link Systems Inc. | ER8411 V1 | affected 1.4.1 Build 20260708 Rel.64832 custom | Not specified |
| CNA | TP-Link Systems Inc. | ER706W V1 | affected 1.2.11 Build 20260723 Rel.41567 custom | Not specified |
| CNA | TP-Link Systems Inc. | ER706W-4G V1 | affected 1.2.6 Build 20260723 Rel.41321 custom | Not specified |
| CNA | TP-Link Systems Inc. | ER706W-4G V2 | affected 2.1.11 Build 20260723 Rel.41624 custom | Not specified |
| CNA | TP-Link Systems Inc. | ER706WP-4G V1 | affected 1.1.11 Build 20260723 Rel.41624 custom | Not specified |
| CNA | TP-Link Systems Inc. | ER703WP-4G-Outdoor V1 | affected 1.1.7 Build 20260723 Rel.41712 custom | Not specified |
| CNA | TP-Link Systems Inc. | DR3220v-4G V1 | affected 1.2.0 Build 20260630 Rel.82652 custom | Not specified |
| CNA | TP-Link Systems Inc. | DR3650v V1 | affected 1.2.0 Build 20260630 Rel.83311 custom | Not specified |
| CNA | TP-Link Systems Inc. | DR3650v-4G V1 | affected 1.2.0 Build 20260630 Rel.83347 custom | Not specified |
| CNA | TP-Link Systems Inc. | ER603WP-4G-Outdoor V1 | affected 1.0.2 Build 20260723 Rel.43271 custom | Not specified |
| CNA | TP-Link Systems Inc. | DR3150 V1 | affected 1.0.1 Build 20260722 Rel.16854 custom | Not specified |
| CNA | TP-Link Systems Inc. | ER701-5G-Outdoor V1 | affected 1.0.3 Build 20260723 Rel.40931 custom | Not specified |
| CNA | TP-Link Systems Inc. | ER605W V2 | affected 2.0.4 Build 20260723 Rel.43763 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.tp-link.com/us/support/faq/5256 | f23511db-6c3e-4e32-a477-6aa17d310630 | www.tp-link.com | |
| www.omadanetworks.com/us/support/download | f23511db-6c3e-4e32-a477-6aa17d310630 | www.omadanetworks.com | |
| www.omadanetworks.com/en/support/download | f23511db-6c3e-4e32-a477-6aa17d310630 | www.omadanetworks.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Yoontae Lee (@yunttai) (en)
There are currently no legacy QID mappings associated with this CVE.