CVE-2026-4648
Received Received - Intake

Insecure Cryptographic Algorithm in CasfID NFC Wristband Payment System

Vulnerability report for CVE-2026-4648, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)

Description

Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. (version used at Resurrection Fest 2025), which employs cards based on MIFARE Classic technology (FM11RF08S). The cryptographic weakness of the authentication algorithm allows an attacker to retrieve access keys using techniques known as Backdoored Nested Attack, read the wristband’s entire contents, and clone its credentials onto a compatible rewritable card. Exploitation of this vulnerability could enable the impersonation of other attendees, the fraudulent use of the balance associated with their wristbands, and financial losses for both the affected users and the event organizers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
casfid_servicios_tecnologicos mifare_classic to 3.0 (exc)
casfid_servicios_tecnologicos cashless_payment_system_using_nfc_wristbands *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-326 The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an insecure cryptographic algorithm in CasfID Servicios Tecnológicos' cashless payment system using NFC wristbands based on MIFARE Classic technology (FM11RF08S). Attackers can exploit this weakness to retrieve access keys using techniques like the Backdoored Nested Attack, read the wristband's contents, and clone credentials onto a rewritable card. This allows impersonation of attendees and fraudulent use of wristband balances.

Detection Guidance

Detection requires checking if MIFARE Classic chips (FM11RF08S) are in use. Inspect wristbands or payment terminals for MIFARE Classic branding or FM11RF08S markings. Use RFID diagnostic tools like Proxmark3 or Flipper Zero to read chip details and verify cryptographic weaknesses.

Impact Analysis

If affected, you could face financial losses due to fraudulent use of your wristband balance. Your credentials could be cloned, allowing attackers to impersonate you at events. Both users and event organizers may suffer financial harm as a result of this vulnerability.

Compliance Impact

This vulnerability primarily affects data confidentiality and integrity due to the insecure cryptographic algorithm in the NFC wristbands. While GDPR focuses on personal data protection and HIPAA on health information, this flaw could lead to unauthorized access to sensitive attendee data stored on the wristbands, potentially violating these regulations if personal or health-related information is compromised.

Mitigation Strategies

Stop using MIFARE Classic chips immediately. Replace them with MIFARE DESFire (EV2 or EV3) using AES-128 or stronger encryption. Update all NFC wristbands and payment terminals to the new hardware.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-4648. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart