• News/
  • https://www.bleepingcomputer.com/news/security/unsaflok-flaw-can-let-hackers-unlock-millions-of-hotel-doors/

Unsaflok flaw can let hackers unlock millions of hotel doors

BleepingComputer
·
Bill Toulas
·
Published Mar 21, 2024
·
Updated

Researchers disclosed vulnerabilities today that impact 3 million Saflok electronic RFID locks deployed in 13,000 hotels and homes worldwide, allowing the researchers to easily unlock any door in a hotel by forging a pair of keycards. The series of security flaws, dubbed "Unsaflok," was discovered by researchers Lennert Wouters, Ian Carroll, rqu, BusesCanFly, Sam Curry, shell, and Will Caruana in September 2022. As first reported by Wired, the researchers were invited to a private hacking event in Las Vegas, where they competed with other teams to find vulnerabilities in a hotel room and all the devices within it. The team of researchers focused on finding vulnerabilities in the Saflok electronic lock for the hotel room, discovering security flaws that could open any door within the hotel. The researchers disclosed their findings to manufacturer Dormakaba in November 2022, allowing the vendor to work on mitigations and inform hotels of the security risk without publicizing the issue. However, the researchers note that the flaws have been available for over 36 years, so while there have been no confirmed cases of exploitation in the wild, the extensive exposure period increases that possibility. "While we are not aware of any real-world attacks that use these vulnerabilities, it is not impossible that these vulnerabilities are known, and have been used, by others," explains the Unsaflok team. Today, the researchers publicly disclosed the Unsaflok vulnerabilities for the first...

Read full article

Affected Software

7 affected components
dormakaba Saflok MT
dormakaba Quantum Series
dormakaba RT Series
dormakaba Saffire Series
dormakaba Confidant Series
dormakaba System 6000
dormakaba Ambiance

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses vulnerabilities in Saflok electronic RFID locks that can be exploited by hackers to unlock hotel doors.

2

What security implications are discussed?

The article highlights the risk of unauthorized access to hotel rooms due to the ability to forge keycards.

3

How many locks are affected by the vulnerability?

Approximately 3 million Saflok electronic locks deployed in 13,000 hotels and homes are affected.

4

What companies and products are involved in this security issue?

The vulnerabilities affect multiple products from Dormakaba, including the Saflok MT, Quantum Series, RT Series, Saffire Series, Confidant Series, System 6000, and Ambiance.

5

What should hotel management do in response to this flaw?

Hotel management should urgently assess their locking systems and apply any available security patches or updates provided by Dormakaba.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203