TP-Link Captive Portal Session Termination (CVE-2026-9033)
CVE-2026-9033 Published on August 20, 2026
Unauthenticated Captive Portal Session Termination and Forced Logout in Omada Gateways
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access.
Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate.
Vulnerability Analysis
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Affected Versions
TP-Link Systems Inc. ER7212PC v2:- Before 2.4.3 Build 20260722 Rel.40250 is affected.
- Before 2.4.4 Build 20260630 Rel.14398 is affected.
- Before 2.3.5 Build 20260625 Rel.43136 is affected.
- Before 1.3.4 Build 20260625 Rel.43136 is affected.
- Before 1.4.4 Build 20260625 Rel.43063 is affected.
- Before 1.2.0 Build 20260630 Rel.82947 is affected.
- Before 1.4.1 Build 20260708 Rel.64832 is affected.
- Before 1.2.11 Build 20260723 Rel.41567 is affected.
- Before 1.2.6 Build 20260723 Rel.41321 is affected.
- Before 2.1.11 Build 20260723 Rel.41624 is affected.
- Before 1.1.11 Build 20260723 Rel.41624 is affected.
- Before 1.1.7 Build 20260723 Rel.41712 is affected.
- Before 1.2.0 Build 20260630 Rel.82652 is affected.
- Before 1.2.0 Build 20260630 Rel.83311 is affected.
- Before 1.2.0 Build 20260630 Rel.83347 is affected.
- Before 1.0.2 Build 20260723 Rel.43271 is affected.
- Before 1.0.1 Build 20260722 Rel.16854 is affected.
- Before 1.0.3 Build 20260723 Rel.40931 is affected.
- Before 2.0.4 Build 20260723 Rel.43763 is affected.