Insecure Cryptographic Algorithm in CasfID NFC Payment System
CVE-2026-4648

6.8MEDIUM

What is CVE-2026-4648?

The cashless payment system utilizing NFC wristbands from CasfID Servicios Tecnol贸gicos S.L.U. has been identified to employ an insecure cryptographic algorithm, specifically in the version used during Resurrection Fest 2025. This vulnerability stems from the reliance on MIFARE Classic technology, enabling attackers to execute Backdoored Nested Attacks. This allows unauthorized retrieval of access keys, resulting in potential cloning of the initial wristband's credentials onto a compatible rewritable card. The exploitation of this weakness poses significant risks, including impersonation of event attendees and unauthorized transactions, leading to financial implications for both users and event organizers.

Affected Version(s)

NFC Wristbands FM11RF08S variant

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luis Miranda Acebedo
.