Impact
An attacker with access to a device’s captive portal service, without needing credentials, can terminate any active sessions. This allows the attacker to force users to log in again or clear all present sessions, disrupting normal access without compromising the device itself. The flaw is a missing authentication check for session control functions (CWE‑306).
Affected Systems
TP‑Link Systems Inc. devices including the DR3150 v1, DR3220v‑4G v1, DR3650v v1, DR3650v‑4G v1, ER603WP‑4G‑Outdoor v1, ER605 v2, ER605W v2, ER701‑5G‑Outdoor v1, ER703WP‑4G‑Outdoor v1, ER706W v1, ER706W‑4G v1, ER706W‑4G v2, ER706WP‑4G v1, ER707‑M2 v1, ER7206 v2, ER7212PC v2, ER8411 v1, ER7406 v1, and ER7412‑M2 v1.
Risk and Exploitability
The vulnerability has a CVSS score of 6, indicating medium severity. EPSS data is unavailable and the issue is not listed in the CISA KEV catalog, implying no known wide‑scale exploitation yet. An attacker who can reach the portal service—likely a local or intruder network—can directly exploit the flaw to terminate sessions without authentication, causing temporary disruption and forced re‑authentication for affected users.
OpenCVE Enrichment