CVE Explorer
CVE-2026-4648
Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. (version used at Resurrection Fest 2025), which employs cards based on MIFARE Classic technology (FM11RF08S). The cryptographic weakness of the authentication algorithm allows an attacker to retrieve access keys using techniques known as Backdoored Nested Attack, read the wristband’s entire contents, and clone its credentials onto a compatible rewritable card.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"NFC Wristbands","vendor":"CasfID Servicios Tecnológicos","versions":[{"status":"affected","version":"FM11RF08S variant","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9b86cbd1a9352df8e7e1c2bff8d99a21e0eac19d24bdff7917552d9eb6ae1bf1 · sha256:09655e11ef5246c8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"PHYSICAL","baseScore":6.8,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9b86cbd1a9352df8e7e1c2bff8d99a21e0eac19d24bdff7917552d9eb6ae1bf1 · sha256:09655e11ef5246c8… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-326","description":"CWE-326: Inadequate Encryption Strength","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9b86cbd1a9352df8e7e1c2bff8d99a21e0eac19d24bdff7917552d9eb6ae1bf1 · sha256:09655e11ef5246c8… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/insufficient-encryption-level-casfid-servicios-tecnologicos-nfc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9b86cbd1a9352df8e7e1c2bff8d99a21e0eac19d24bdff7917552d9eb6ae1bf1 · sha256:09655e11ef5246c8… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.