PT-2026-97916 · Norwegian Cruise Line · Door Access Controllers
CVE-2026-75907
·
Published
2026-09-24
·
Updated
2026-09-28
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Norwegian Cruise Line door access controllers (affected versions not specified)
Description
An authentication bypass exists in RFID-based door access controllers where the system grants entry based solely on the static 7-byte UID of an NTAG212 NFC chip. The UID is a manufacturer serial number broadcast in plaintext during every read and is intended for identification rather than authentication. Because the system lacks a challenge-response mechanism, the credential can be easily captured using NFC-capable devices and cloned onto writable tags. The reader ignores the tag memory blocks containing signatures and printed serial numbers, rendering those security features ineffective.
Recommendations
Update the reader firmware to enforce cryptographic challenge-response mechanisms, such as utilizing the NTAG212 signature or migrating to MIFARE DESFire.
Fix
Improper Authentication
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Door Access Controllers