Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access. Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate. | |
| Title | Unauthenticated Captive Portal Session Termination and Forced Logout in Omada Gateways | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-08-20T18:59:36.657Z
Reserved: 2026-05-19T16:30:37.346Z
Link: CVE-2026-9033
Updated: 2026-08-20T18:59:33.402Z
Status : Received
Published: 2026-08-20T19:17:04.950
Modified: 2026-08-20T19:17:04.950
Link: CVE-2026-9033
No data.
OpenCVE Enrichment
No data.
-
CWE-306
Missing Authentication for Critical Function