Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-4648— Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands

CVSS 6.8 · Medium EPSS 0.12% · P2

Affected Version Matrix 1

VendorProductVersion RangeStatus
CasfID Servicios TecnológicosNFC WristbandsFM11RF08S variantaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-4648

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands
Source: CVE Program / CVE List V5
Vulnerability Description
Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. (version used at Resurrection Fest 2025), which employs cards based on MIFARE Classic technology (FM11RF08S). The cryptographic weakness of the authentication algorithm allows an attacker to retrieve access keys using techniques known as Backdoored Nested Attack, read the wristband’s entire contents, and clone its credentials onto a compatible rewritable card. Exploitation of this vulnerability could enable the impersonation of other attendees, the fraudulent use of the balance associated with their wristbands, and financial losses for both the affected users and the event organizers.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的加密强度
Source: CVE Program / CVE List V5
Vulnerability Title
CasfID Servicios Tecnológicos NFC Wristbands 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
CasfID Servicios Tecnológicos NFC Wristbands是CasfID Servicios Tecnológicos公司的一款基于NFC技术的腕带式门禁设备。 CasfID Servicios Tecnológicos NFC Wristbands存在加密问题漏洞,该漏洞源于使用了不安全的加密算法,即基于MIFARE Classic技术的认证算法存在加密弱点,允许攻击者通过Backdoored Nested Attack技术检索访问密钥、读取腕带全部内容并克隆凭据,可能导致
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
CasfID Servicios TecnológicosNFC Wristbands FM11RF08S variant -

II. Public POCs for CVE-2026-4648

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-4648

登录查看更多情报信息。

Vendor Advisories for CVE-2026-4648 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-4648

No comments yet


Leave a comment