VU#676317: Norwegian Cruise Line door access controller contains an improper authentication vulnerability
CERT warns Norwegian Cruise Line door readers accept cloned RFID UIDs, allowing forged keycards into restricted ship areas.
CERT/CC published VU#676317 for CVE-2026-75907, an improper authentication flaw in door access controllers used on Norwegian Cruise Line ships. Readers accept NFC credentials based only on a static 7-byte UID and do not inspect NTAG212 memory that holds a printed serial and a signature-like value. Someone briefly near a valid card can capture the UID and copy it to an inexpensive writable card that the readers treat as genuine. CERT could not coordinate with the vendor and suggests RFID-blocking sleeves, foil shielding, and keeping cards away from other people and devices.