CVE-2026-9033
CVE-2026-9033 is a medium-severity vulnerability in Tp-link Er7212pc Firmware with a CVSS 3.x base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-306.
Key facts
- Severity: Medium (CVSS 3.x base score 4.3)
- CVSS v4: 6.0
- EPSS exploit prediction: 0% (18th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-306
- Affected product: Tp-link Er7212pc Firmware
- Published:
- Last modified:
Description
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access. Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate.
Frequently asked questions
- What is CVE-2026-9033?
- An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access. Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate.
- How severe is CVE-2026-9033?
- CVE-2026-9033 has a CVSS 3.x base score of 4.3, rated medium severity. It is exploitable over an adjacent network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability low.
- Is CVE-2026-9033 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (18th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-9033?
- CVE-2026-9033 primarily affects Tp-link Er7212pc Firmware. In total, 18 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-9033?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-9033 published?
- CVE-2026-9033 was published on 2026-08-20 and last updated on 2026-09-08.
References
- https://www.omadanetworks.com/en/support/download/
- https://www.omadanetworks.com/us/support/download/
- https://www.tp-link.com/us/support/faq/5256/
Affected products (18)
- cpe:2.3:o:tp-link:er7212pc_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:er605_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:er7206_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:er7406_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:er707-m2_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:er7412-m2_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:er8411_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:er706w_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:er706w-4g_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:er706wp-4g_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:er703wp-4g-outdoor_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:dr3220v-4g_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:dr3650v_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:dr3650v-4g_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:er603wp-4g-outdoor_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:dr3150_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:er701-5g-outdoor_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:tp-link:er605w_firmware:*:*:*:*:*:*:*:*
More vulnerabilities in Tp-link Er7212pc Firmware
- CVE-2026-19586 — Critical (CVSS 9.8): A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as…
- CVE-2025-7851 — Critical (CVSS 9.8): An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
- CVE-2025-6542 — Critical (CVSS 9.8): An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
- CVE-2025-6541 — High (CVSS 8.8): An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
- CVE-2026-19683 — High (CVSS 7.4): A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a…
- CVE-2025-7850 — High (CVSS 7.2): A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
All CVEs affecting Tp-link Er7212pc Firmware →
Other CWE-306 (Missing Authentication for Critical Function) vulnerabilities
- CVE-2026-63692 — Critical (CVSS 10.0): Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function…
- CVE-2026-63688 — Critical (CVSS 10.0): Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical…
- CVE-2026-103956 — Critical (CVSS 10.0): Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed…
- CVE-2026-53988 — Critical (CVSS 10.0): Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows…
- CVE-2026-85889 — Critical (CVSS 10.0): Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges…
- CVE-2026-92808 — Critical (CVSS 10.0): A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An…
Browse all CWE-306 (Missing Authentication for Critical Function) vulnerabilities →