HIGH
Norwegian Cruise Line
CVE published 2026-09-24
CVE-2026-75907
A Norwegian Cruise Line asset's door access control system uses NTAG212 NFC chips with static 7-byte UIDs for authentication, which is insecure because UIDs are sent in the clear and not secret. This allows for easy copying of credentials, as the system only performs identification, not authentication, and lacks challenge-response capabilities. The CVE-2026-75907 vulnerability in Norwegian Cruise Line's d [truncated]