Session Termination Vulnerability in TP-Link Omada Gateway
CVE-2026-9033

6MEDIUM

Key Information:

Vendor
CVE Published:
20 August 2026

What is CVE-2026-9033?

An unauthenticated attack on the captive portal service of affected TP-Link Omada Gateway devices may enable attackers to terminate individual or all active sessions. This vulnerability permits unauthorized logout of specific users, resulting in temporary service disruption. Users must re-authenticate to restore their access, potentially affecting operational continuity and user experience.

Affected Version(s)

DR3150 v1 0 < 1.0.1 Build 20260722 Rel.16854

DR3220v-4G v1 0 < 1.2.0 Build 20260630 Rel.82652

DR3650v v1 0 < 1.2.0 Build 20260630 Rel.83311

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yoontae Lee (@yunttai)
.