CVE-2026-75907

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.5
HIGH

Description

The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. A UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to authenticate the holder. Validating on the UID of the NTAG212 NFC chip alone is identification, not authentication, and the credential has no challenge-response capability that would resist copying.

Published
September 24, 2026 4:17 PM
Last Modified
September 24, 2026 7:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-287 CWE-294 CWE-613

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.