securityonline.info 25 Sept 2026, 13:06 UTC

Cruise Ship Door Flaw Lets Attackers Clone RFID Cards for Access

Cruise Ship Door Flaw Lets Attackers Clone RFID Cards for Access
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CERT /CC has described an improper authentication flaw, CVE-2026-75907, in shipboard door-access controllers used by Norwegian Cruise Line. Rated 7.5 High under CVSSv3, the issue affects controllers that use unencrypted NTAG212 RFID cards. The readers reportedly authenticate cards using only their static seven-byte unique identifier (UID), treating identification as authentication and failing to check available integrity data.

An attacker within a few inches of a card could read its UID with low-cost RFID equipment and copy it to a blank card. Because the system does not perform a cryptographic challenge, the cloned card may be accepted by affected readers, potentially allowing access to passenger cabins or restricted crew areas. The report says there has been no confirmed exploitation, and no public proof-of-concept code has been released.

CERT/CC reportedly could not establish contact with the vendor before publication, so no official firmware patch is available. Until operators replace or update affected hardware, the report recommends shielding cards in RFID-blocking sleeves or wallets; aluminium foil is suggested as an improvised barrier. Passengers are also advised to avoid bringing cards close to unfamiliar devices in crowded areas.

View full article

Article by CyberSIXT