Junglewise Threat Intelligence

CVE-2026-9033: TP-Link Deco captive portal session termination denial of service

CVE-2026-9033 · Severity: medium · CVSS 4.3 · Published 2026-08-20

Technologies: TP-Link Deco BE65, TP-Link Deco BE65 Pro, TP-Link Deco BE85, TP-Link Deco BE23, TP-Link Deco BE65-PoE, TP-Link Deco BE25. Vendors: TP-Link.

Executive brief

TP-Link Deco mesh WiFi routers include a captive portal service that manages guest network access and authentication. An unauthenticated attacker with network access can remotely terminate active captive portal sessions, forcing users to re-authenticate and causing temporary service disruption for legitimate guests on affected networks.

Technical details

The vulnerability is a denial-of-service flaw in the captive portal service of affected TP-Link Deco mesh WiFi systems. An unauthenticated network-adjacent attacker can send requests to terminate individual or all active captive portal sessions without authentication. The attack requires only network connectivity to the captive portal service (typically the router itself or guest network). Successful exploitation forces targeted users to re-authenticate, disrupting access temporarily but not compromising authentication credentials or persistent data. Patches should be available through TP-Link firmware updates.

Affected products

  • TP-Link Deco BE25 US V1
  • TP-Link Deco BE23 US V1
  • TP-Link Deco BE85 EU V1, V3
  • TP-Link Deco BE65 EU V1, V3
  • TP-Link Deco BE65 Pro EU V1
  • TP-Link Deco BE65-PoE EU V1
  • TP-Link Deco BE25-Outdoor US V1
  • TP-Link Deco WB14400 US V1
  • TP-Link Deco WB7200 US V1
  • TP-Link Deco WB10800 US V1

Timeline

  • 2026-08-20: disclosed: CVE-2026-9033 published on NVD

References