CVE-2026-4648
Last modified
CVE-2026-4648 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. (version used at Resurrection Fest 2025), which employs cards based on MIFARE Classic technology (FM11RF08S).
Description
Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. (version used at Resurrection Fest 2025), which employs cards based on MIFARE Classic technology (FM11RF08S). The cryptographic weakness of the authentication algorithm allows an attacker to retrieve access keys using techniques known as Backdoored Nested Attack, read the wristband’s entire contents, and clone its credentials onto a compatible rewritable card. Exploitation of this vulnerability could enable the impersonation of other attendees, the fraudulent use of the balance associated with their wristbands, and financial losses for both the affected users and the event organizers.
Metrics
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| CasfID Servicios Tecnológicos | NFC Wristbands | FM11RF08S variant |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-4648?
How severe is CVE-2026-4648?
How do I fix CVE-2026-4648?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-46474Trog::TOTP versions before 1.006 for Perl generate secrets u…7.5
- CVE-2026-46475Flowise is a drag & drop user interface to build a customize…8.8
- CVE-2026-46476Flowise is a drag & drop user interface to build a customize…8.8
- CVE-2026-46477Flowise is a drag & drop user interface to build a customize…8.8
- CVE-2026-46478Flowise is a drag & drop user interface to build a customize…8.8
- CVE-2026-46479Flowise is a drag & drop user interface to build a customize…8.8
- CVE-2026-46480Flowise is a drag & drop user interface to build a customize…8.8
- CVE-2026-46481OpenMetadata is a unified metadata platform. Prior to versio…8.3
- CVE-2026-46483Vim is an open source, command line text editor. Prior to 9.…7
- CVE-2026-46484Headplane is a feature-complete Web UI for Headscale. Prior …8.1
- CVE-2026-46485Dashy is a self-hostable personal dashboard. Prior to 4.0.8,…8.2
- CVE-2026-46486MVT (Mobile Verification Toolkit) helps with conducting fore…5.3
Are you affected by CVE-2026-4648?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
