CVE-2026-9033Medium· 4.3▾ SunlitAn unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
0.2% → 0.2%
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access.
Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate.
er7212pc_firmware < 2.4.3er605_firmware < 2.4.4er7206_firmware < 2.3.5er7406_firmware < 1.3.4er707-m2_firmware < 1.4.4er7412-m2_firmware < 1.2.0er8411_firmware < 1.4.1er706w_firmware < 1.2.11er706w-4g_firmware < 1.2.6er706w-4g_firmware < 2.1.11er706wp-4g_firmware < 1.1.11er703wp-4g-outdoor_firmware < 1.1.7dr3220v-4g_firmware < 1.2.0dr3650v_firmware < 1.2.0dr3650v-4g_firmware < 1.2.0er603wp-4g-outdoor_firmware < 1.0.2dr3150_firmware < 1.0.1er701-5g-outdoor_firmware < 1.0.3er605w_firmware < 2.0.4Upgrade past the affected range:
er7212pc_firmware 2.4.3er605_firmware 2.4.4er7206_firmware 2.3.5er7406_firmware 1.3.4er707-m2_firmware 1.4.4er7412-m2_firmware 1.2.0er8411_firmware 1.4.1er706w_firmware 1.2.11er706w-4g_firmware 2.1.11er706wp-4g_firmware 1.1.11er703wp-4g-outdoor_firmware 1.1.7dr3220v-4g_firmware 1.2.0dr3650v_firmware 1.2.0dr3650v-4g_firmware 1.2.0er603wp-4g-outdoor_firmware 1.0.2dr3150_firmware 1.0.1er701-5g-outdoor_firmware 1.0.3er605w_firmware 2.0.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-19683High· 7.4A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways
CVE-2025-14300High· 8.1The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authentication
CVE-2019-1895Critical· 9.8A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative …
CVE-2026-2603High· 8.1A flaw was found in Keycloak
CVE-2019-5591Medium· 6.5A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
CVE-2024-0012Critical· 9.8An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…