CVE-2026-75907: Security vulnerability
The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. A UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to authenticate the holder. Validating on the UID of the NTAG212 NFC chip alone is identification, not authentication, and the credential has no challenge-response capability that would resist copying.
Event History
Frequently Asked Questions
What does an attacker need to gain unauthorized entry?
An attacker needs the static 7-byte UID from a valid NTAG212-based credential. The UID is transmitted in cleartext on every read and can be copied because the credential does not use challenge-response authentication.
Who is realistically exposed?
Access-controlled areas protected by the affected Norwegian Cruise Line asset's NTAG212 credentials are exposed if the reader grants entry based solely on the credential UID. Anyone able to obtain a valid credential's UID could potentially present a copied credential.
What can be done if the access-control system cannot be changed immediately?
The provided information does not identify a compensating technical control. Since UID-only validation cannot distinguish an original credential from a copy, physical and operational controls would be needed until authentication that resists copying is deployed.