TL;DR
CERT/CC published an advisory detailing an improper authentication flaw in shipboard door controllers. This Norwegian Cruise Line vulnerability allows attackers to clone passenger keycards by copying static identification data. Guests and crew must adopt physical shielding techniques to protect against unauthorized cabin access.
- CVE: CVE-2026-75907
- CVSS: 7.5 (High · CVSSv3)
- Product: Norwegian Cruise Line door access control
- Affected: N/A
- Impact: CVE-2026-75907
- Status: No confirmed exploitation yet
- EPSS: 0.4% (30-day)
- Action: See vendor advisory
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 7 daysWhy It Matters
Industry reports estimate that Norwegian Cruise Line carries over two million passengers across its global fleet each year. Consequently, weaknesses in cabin locking mechanisms present direct risks to guest safety and vessel operations. Attackers who clone access badges can enter private staterooms or sensitive crew areas.
Fortunately, CERT/CC confirmed that no known active exploitation in the wild has been observed. Additionally, researchers have not released public proof-of-concept exploit code. However, the physical replication of these cards requires only low-cost RFID equipment. Therefore, this Norwegian Cruise Line vulnerability demands immediate operational vigilance from travelers and maritime security personnel.
How The Attack Works
The security defect exists within the reader logic of shipboard electronic door locks. According to the CERT/CC vulnerability note, the readers verify NFC credentials using only their static seven-byte unique identifier (UID). The advisory emphasizes that “Validation based solely on UID constitutes identification rather than authentication.”
Furthermore, the system ignores available integrity safeguards. The advisory notes, “the reader does not inspect this data during the access-control process.” An attacker standing within a few inches of a target can read the static UID. Then, they write the captured value onto an inexpensive blank card. Because the system performs no cryptographic challenge, the reader accepts the forged card immediately.
Affected Versions
This issue affects RFID door access controllers deployed across Norwegian Cruise Line vessels that rely on unencrypted NTAG212 cards.
Patch Or Mitigation Steps
CERT/CC stated that coordinators were unable to establish contact with the vendor before publication. Therefore, no official firmware patches currently exist for affected door locks.
Consequently, travelers must protect themselves through physical countermeasures. Users should place their cruise badges inside RFID-blocking sleeves or shielded wallets to block stray radio signals. Alternatively, wrapping keycards in aluminum foil creates an improvised Faraday barrier. Guests should also maintain physical distance from unfamiliar devices in crowded public ship areas. Applying these steps limits exposure to this Norwegian Cruise Line vulnerability until ship operators update their hardware.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!