CVE-2026-9033

MEDIUM CVSS 4.0: 6.0 EPSS 0.20%
Updated Sep 08, 2026
TP-Link
Parameter Value
CVSS 6.0 (MEDIUM)
Affected Versions before 2.4.4
Fixed In 2.4.3
Type CWE-306 (Missing Authentication for Critical Function)
Vendor TP-Link
Public PoC No

An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access.  Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate.

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products 38

Configuration From (including) Up to (excluding)
Tp-Link Er7212pc_Firmware
cpe:2.3:o:tp-link:er7212pc_firmware:*:*:*:*:*:*:*:*
2.4.3
Tp-Link Er7212pc
cpe:2.3:h:tp-link:er7212pc:2.0:*:*:*:*:*:*:*
Tp-Link Er605_Firmware
cpe:2.3:o:tp-link:er605_firmware:*:*:*:*:*:*:*:*
2.4.4
Tp-Link Er605
cpe:2.3:h:tp-link:er605:2.0:*:*:*:*:*:*:*
Tp-Link Er7206_Firmware
cpe:2.3:o:tp-link:er7206_firmware:*:*:*:*:*:*:*:*
2.3.5
Tp-Link Er7206
cpe:2.3:h:tp-link:er7206:2.0:*:*:*:*:*:*:*
Tp-Link Er7406_Firmware
cpe:2.3:o:tp-link:er7406_firmware:*:*:*:*:*:*:*:*
1.3.4
Tp-Link Er7406
cpe:2.3:h:tp-link:er7406:-:*:*:*:*:*:*:*
Tp-Link Er707-M2_Firmware
cpe:2.3:o:tp-link:er707-m2_firmware:*:*:*:*:*:*:*:*
1.4.4
Tp-Link Er707-M2
cpe:2.3:h:tp-link:er707-m2:-:*:*:*:*:*:*:*
Tp-Link Er7412-M2_Firmware
cpe:2.3:o:tp-link:er7412-m2_firmware:*:*:*:*:*:*:*:*
1.2.0
Tp-Link Er7412-M2
cpe:2.3:h:tp-link:er7412-m2:-:*:*:*:*:*:*:*
Tp-Link Er8411_Firmware
cpe:2.3:o:tp-link:er8411_firmware:*:*:*:*:*:*:*:*
1.4.1
Tp-Link Er8411
cpe:2.3:h:tp-link:er8411:-:*:*:*:*:*:*:*
Tp-Link Er706w_Firmware
cpe:2.3:o:tp-link:er706w_firmware:*:*:*:*:*:*:*:*
1.2.11
Tp-Link Er706w
cpe:2.3:h:tp-link:er706w:-:*:*:*:*:*:*:*
Tp-Link Er706w-4g_Firmware
cpe:2.3:o:tp-link:er706w-4g_firmware:*:*:*:*:*:*:*:*
1.2.6
Tp-Link Er706w-4g
cpe:2.3:h:tp-link:er706w-4g:-:*:*:*:*:*:*:*
Tp-Link Er706w-4g_Firmware
cpe:2.3:o:tp-link:er706w-4g_firmware:*:*:*:*:*:*:*:*
2.1.11
Tp-Link Er706w-4g
cpe:2.3:h:tp-link:er706w-4g:2.0:*:*:*:*:*:*:*
Tp-Link Er706wp-4g_Firmware
cpe:2.3:o:tp-link:er706wp-4g_firmware:*:*:*:*:*:*:*:*
1.1.11
Tp-Link Er706wp-4g
cpe:2.3:h:tp-link:er706wp-4g:-:*:*:*:*:*:*:*
Tp-Link Er703wp-4g-Outdoor_Firmware
cpe:2.3:o:tp-link:er703wp-4g-outdoor_firmware:*:*:*:*:*:*:*:*
1.1.7
Tp-Link Er703wp-4g-Outdoor
cpe:2.3:h:tp-link:er703wp-4g-outdoor:-:*:*:*:*:*:*:*
Tp-Link Dr3220v-4g_Firmware
cpe:2.3:o:tp-link:dr3220v-4g_firmware:*:*:*:*:*:*:*:*
1.2.0
Tp-Link Dr3220v-4g
cpe:2.3:h:tp-link:dr3220v-4g:-:*:*:*:*:*:*:*
Tp-Link Dr3650v_Firmware
cpe:2.3:o:tp-link:dr3650v_firmware:*:*:*:*:*:*:*:*
1.2.0
Tp-Link Dr3650v
cpe:2.3:h:tp-link:dr3650v:-:*:*:*:*:*:*:*
Tp-Link Dr3650v-4g_Firmware
cpe:2.3:o:tp-link:dr3650v-4g_firmware:*:*:*:*:*:*:*:*
1.2.0
Tp-Link Dr3650v-4g
cpe:2.3:h:tp-link:dr3650v-4g:-:*:*:*:*:*:*:*
Tp-Link Er603wp-4g-Outdoor_Firmware
cpe:2.3:o:tp-link:er603wp-4g-outdoor_firmware:*:*:*:*:*:*:*:*
1.0.2
Tp-Link Er603wp-4g-Outdoor
cpe:2.3:h:tp-link:er603wp-4g-outdoor:-:*:*:*:*:*:*:*
Tp-Link Dr3150_Firmware
cpe:2.3:o:tp-link:dr3150_firmware:*:*:*:*:*:*:*:*
1.0.1
Tp-Link Dr3150
cpe:2.3:h:tp-link:dr3150:-:*:*:*:*:*:*:*
Tp-Link Er701-5g-Outdoor_Firmware
cpe:2.3:o:tp-link:er701-5g-outdoor_firmware:*:*:*:*:*:*:*:*
1.0.3
Tp-Link Er701-5g-Outdoor
cpe:2.3:h:tp-link:er701-5g-outdoor:-:*:*:*:*:*:*:*
Tp-Link Er605w_Firmware
cpe:2.3:o:tp-link:er605w_firmware:*:*:*:*:*:*:*:*
2.0.4
Tp-Link Er605w
cpe:2.3:h:tp-link:er605w:2.0:*:*:*:*:*:*:*