VORANT. Threat Intelligence Sign in Create a free account

RFID UID cloning bypasses NCL ship door locks

routine vulnerability transportation

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Norwegian Cruise Line door access readers accept cloned RFID UIDs, letting anyone with brief proximity to a keycard forge a working duplicate.

CERT/CC published VU#676317 describing an improper authentication vulnerability (CVE-2026-75907) in RFID-based door access controllers used aboard Norwegian Cruise Line ships. The readers authenticate NFC keycards solely by checking the card's static 7-byte UID rather than performing any cryptographic challenge-response. Because a UID is not secret and the NTAG212 tags used do not require validation of their signed serial-number block during access checks, the system provides identification only, not real authentication.

An attacker who briefly gets within a few centimeters of a legitimate keycard (e.g., 1-2 inches for 13.56 MHz cards) can capture its UID with an inexpensive RFID reader/writer without touching or altering the original card, then write that UID to a blank UID-writable card to produce a permanent, fully functional duplicate credential. Depending on logging configuration, such unauthorized entries may be indistinguishable from legitimate access, which is particularly concerning given that these controllers guard restricted areas on a passenger vessel with direct safety implications.

CERT/CC was unable to identify or coordinate with the vendor, so no patch exists. Mitigations are limited to physical countermeasures: RFID-blocking wallets/sleeves, DIY foil shielding, and maintaining physical distance from unknown readers/devices. There is no indication of in-the-wild exploitation; this is a disclosed design weakness rather than an observed attack campaign. Defenders operating similar UID-only RFID access control systems, particularly in maritime, hospitality, or facility contexts, should treat this as a reminder to move toward cryptographically authenticated credentials (e.g., DESFire EV or similar systems supporting challenge-response) rather than relying on static UID matching.

Mentioned in this report

Vulnerabilities CVE-2026-75907

Source reporting: https://kb.cert.org/vuls/id/676317

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 9,801 reports from 154 sources, 1,536 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs