Insecure Cryptographic Algorithm in CasfID NFC Payment System
CVE-2026-4648
Key Information:
- Status
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-4648?
The cashless payment system utilizing NFC wristbands from CasfID Servicios Tecnol贸gicos S.L.U. has been identified to employ an insecure cryptographic algorithm, specifically in the version used during Resurrection Fest 2025. This vulnerability stems from the reliance on MIFARE Classic technology, enabling attackers to execute Backdoored Nested Attacks. This allows unauthorized retrieval of access keys, resulting in potential cloning of the initial wristband's credentials onto a compatible rewritable card. The exploitation of this weakness poses significant risks, including impersonation of event attendees and unauthorized transactions, leading to financial implications for both users and event organizers.
Affected Version(s)
NFC Wristbands FM11RF08S variant
