Tp-Link Er7212pc Firmware
CVE-2026-9033
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access. Successful exploitation may allow termination of individual or all active captive portal sessions, causing temporary service disruption and requiring users to re-authenticate.
What this means for your business
- It affects Tp-Link Er7212pc Firmware. It matters if your company, or a supplier that handles your data, runs it.
- An attacker can use it from inside the same network, without a login, and without anyone at your company clicking anything.
What to do
- 1Check whether your company or your suppliers run Tp-Link Er7212pc Firmware, and which version. The affected versions are listed further down this page.
- 2If you do, apply the vendor's fix. A patch or vendor advisory has been published.
Not sure if your company is exposed?
Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.
Scoring
- CVSS
- 4.3 (v3.1)
- Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L- CVSS v4
- 6.0
- Weakness
- CWE-306
- Assigned by
- f23511db-6c3e-4e32-a477-6aa17d310630
Dates
- Published
- 2026-08-20
- Last modified
- 2026-09-08
- Sources
- NVD
Affected products
- Tp-Link Er7212pc Firmware- 2.4.3
- Tp-Link Er7212pc2.0
- Tp-Link Er605 Firmware- 2.4.4
- Tp-Link Er6052.0
- Tp-Link Er7206 Firmware- 2.3.5
- Tp-Link Er72062.0
- Tp-Link Er7406 Firmware- 1.3.4
- Tp-Link Er7406all versions
- Tp-Link Er707-M2 Firmware- 1.4.4
- Tp-Link Er707-M2all versions
- Tp-Link Er7412-M2 Firmware- 1.2.0
- Tp-Link Er7412-M2all versions
As listed in the NVD configuration data. Not a statement about your estate.