Session Termination Vulnerability in TP-Link Omada Gateway
CVE-2026-9033
6MEDIUM
Key Information:
- Vendor
Tp-link Systems Inc.
- Vendor
- CVE Published:
- 20 August 2026
What is CVE-2026-9033?
An unauthenticated attack on the captive portal service of affected TP-Link Omada Gateway devices may enable attackers to terminate individual or all active sessions. This vulnerability permits unauthorized logout of specific users, resulting in temporary service disruption. Users must re-authenticate to restore their access, potentially affecting operational continuity and user experience.
Affected Version(s)
DR3150 v1 0 < 1.0.1 Build 20260722 Rel.16854
DR3220v-4G v1 0 < 1.2.0 Build 20260630 Rel.82652
DR3650v v1 0 < 1.2.0 Build 20260630 Rel.83311
