How to test your RFID and access control systems for weaknesses

Youri van der Zwart ·

RFID-based access control systems are everywhere in 2026, from office buildings and data centres to local government facilities and healthcare sites. But many organisations deploy these systems and never test whether they actually hold up against real-world attacks. A structured penetration testing exercise focused on your access control environment can reveal credential cloning risks, software vulnerabilities, and procedural gaps before a malicious actor finds them first. This guide walks you through exactly how to do that, step by step.

Work through each section in order. Some steps require specialist hardware or software, but the methodology itself is applicable whether you are running a small office setup or a multi-site enterprise deployment.

What you need before testing access control systems

Before you touch a single card reader, make sure you have the right authorisation and the right tools in place. Testing access control systems without written permission from the asset owner is illegal in most jurisdictions, and even internal security teams need a signed scope document before they begin.

  • Written authorisation from the system owner, including the scope of testing
  • A list of all access control systems and locations covered by the test
  • An RFID reader/writer device (such as a Proxmark3 or ACR122U, depending on the card technology in use)
  • A laptop with relevant software installed (Proxmark3 client, libnfc, or equivalent)
  • Access to the access control management software or a point of contact who can verify test results
  • A test card or fob that you are authorised to clone or modify
  • A notepad or structured reporting template to log findings in real time

Confirm your testing window with facilities and IT teams so that legitimate alarms or access denials during the test do not trigger an unnecessary incident response. Once authorisation is confirmed and your toolkit is ready, you can move to mapping the environment.

Map your RFID infrastructure and entry points

Start by building a complete picture of every reader, controller, and entry point within scope. You cannot test what you have not identified, and gaps in your map will become gaps in your findings.

  1. Walk every area within scope and photograph or log each reader, noting its location, make, model, and the card technology it uses (for example, HID Prox, MIFARE Classic, MIFARE DESFire, or iCLASS).
  2. Record how each reader connects to its controller, whether that is Wiegand, OSDP, or a proprietary protocol.
  3. Identify any secondary entry points such as emergency exits, loading bays, or server room doors that may sit on a separate controller or have weaker controls than main entrances.
  4. Note which doors have additional controls such as PIN pads, biometrics, or intercoms, and which rely solely on card presentation.

After the walkthrough, cross-reference your map against any existing asset inventory. Discrepancies, such as readers that appear in the building but not in the inventory, are themselves a finding worth flagging. With a complete map in hand, you are ready to start probing for technical vulnerabilities.

Test for credential cloning and replay vulnerabilities

Credential cloning is one of the most common and most impactful weaknesses in RFID-based access control. Older technologies like HID 125kHz Prox cards and MIFARE Classic cards are particularly susceptible because they lack strong encryption or authentication mechanisms.

Cloning legacy credentials

Using your authorised test card, attempt to read the card data with your RFID tool. With a Proxmark3, for example, you would run the appropriate read command for the card frequency (125 kHz for legacy HID, 13.56 MHz for MIFARE). If the card data reads successfully without any authentication challenge, the credential is clonable. Write the captured data to a blank writable card and present it to the reader to confirm whether the clone is accepted.

Testing for replay attacks

Some systems transmit credential data over the Wiegand interface in clear text between the reader and the controller. Use a Wiegand sniffing tool or a Proxmark3 in sniff mode to capture the data transmitted during a legitimate card presentation, then replay that captured signal. If the controller accepts the replayed credential without challenge, the system is vulnerable to replay attacks even if the card itself uses stronger encryption.

After completing both tests, note which card technologies and which entry points were susceptible. Systems using MIFARE DESFire EV2 or EV3 with proper key management, or OSDP with secure channel enabled, should resist both attacks. Any reader that accepted a cloned card or a replayed signal is a high-priority finding.

Probe the access control software and backend

The physical readers are only part of the picture. The software managing access rights, audit logs, and user accounts is equally important to test.

  1. Attempt to access the access control management interface from the network. Check whether it is exposed on the internal network only, or whether it is reachable from guest Wi-Fi or externally.
  2. Test the login page for default credentials. Many access control systems ship with well-known default usernames and passwords that are never changed during installation.
  3. Check whether the management interface enforces multi-factor authentication for administrator accounts.
  4. Review audit log settings to confirm whether all access events (including failed attempts) are being recorded and whether logs are stored in a tamper-evident location.
  5. Check user account hygiene: look for dormant accounts belonging to former employees, contractor accounts with broader access than necessary, and shared credentials.

If you have access to the backend database or API, verify that communications between the reader controllers and the server are encrypted. Unencrypted controller-to-server traffic can expose access events and credential data to anyone with network access. Document every misconfiguration you find, even if it seems minor in isolation, because attackers chain small weaknesses together.

Validate physical and procedural controls

Technical controls only work when physical and procedural layers support them. This section of the test looks at the human and environmental factors that can undermine even a well-configured system.

  1. Test for tailgating: stand near a controlled door during a busy period and observe whether staff challenge or allow entry to people who follow closely behind a badge holder without presenting their own credential.
  2. Check whether doors fully latch and lock after each use. Doors held open by props, worn door closers, or misaligned frames bypass the access control entirely.
  3. Inspect the reader installation. Readers mounted with exposed screws on the unsecured side of a door can be removed and the wiring tampered with to force the door open.
  4. Ask to review the joiner, mover, and leaver process. Confirm that access rights are provisioned and revoked promptly when staff change roles or leave the organisation.

Physical and procedural weaknesses are often the easiest for an attacker to exploit and the easiest for an organisation to overlook because they do not show up in a software scan. Treat them with the same seriousness as a technical vulnerability.

Document findings and prioritise remediation

A penetration test is only as useful as the report that comes out of it. Document every finding clearly enough that someone who was not present during the test can understand what was found, how it was found, and what the risk is.

  1. For each finding, record the location or system affected, the vulnerability identified, the method used to discover it, and the potential impact if exploited.
  2. Assign a risk rating to each finding (critical, high, medium, or low) based on the likelihood of exploitation and the impact on the organisation.
  3. Group findings into categories: credential vulnerabilities, software and backend issues, physical weaknesses, and procedural gaps.
  4. Produce a prioritised remediation list. Critical findings such as cloneable credentials on high-security doors or exposed management interfaces should be addressed immediately. Lower-risk findings can be scheduled into normal change management cycles.
  5. Include recommended remediation actions for each finding, not just a description of the problem.

Share the report with the relevant stakeholders, including facilities management, IT, and, where appropriate, senior leadership, so that remediation is properly resourced and tracked. If you would like support running this process or want an independent review of your access control environment, get in touch with us and we can discuss how we can help.

Frequently Asked Questions

Hoe weet ik welke RFID-kaarttechnologie mijn organisatie gebruikt en of die kwetsbaar is?

V: Hoe weet ik welke RFID-kaarttechnologie mijn organisatie gebruikt en of die kwetsbaar is?nA: Je kunt de kaarttechnologie achterhalen door de specificaties van je toegangscontrolesysteem op te vragen bij de leverancier of facilitaire dienst. Oudere technologieën zoals HID 125kHz Prox en MIFARE Classic zijn doorgaans kwetsbaar voor klonen, terwijl modernere standaarden zoals MIFARE DESFire EV2/EV3 met correct sleutelbeheer aanzienlijk beter bestand zijn tegen aanvallen.

Wat zijn de meest gemaakte fouten bij het uitvoeren van een penetratietest op toegangscontrolesystemen?

V: Wat zijn de meest gemaakte fouten bij het uitvoeren van een penetratietest op toegangscontrolesystemen?nA: De meest voorkomende fout is het testen zonder volledige schriftelijke toestemming en een duidelijk gedefinieerde scope, wat juridische risico's met zich meebrengt. Daarnaast richten organisaties zich te vaak uitsluitend op technische kwetsbaarheden en vergeten ze fysieke en procedurele zwakheden zoals tailgating en verouderde toegangsrechten mee te nemen in de beoordeling.

Wanneer moet een organisatie haar toegangscontrolesystemen opnieuw laten testen?

V: Wanneer moet een organisatie haar toegangscontrolesystemen opnieuw laten testen?nA: Het wordt aanbevolen om toegangscontrolesystemen minimaal jaarlijks te testen, maar ook na significante wijzigingen zoals een verbouwing, uitbreiding van locaties, of een systeemupgrade. Daarnaast is een hertest verstandig na een beveiligingsincident of wanneer er grote personeelswisselingen hebben plaatsgevonden die de toegangsrechten en procedures kunnen hebben beïnvloed.

Hoe prioriteer ik herstelmaatregelen als er meerdere kwetsbaarheden zijn gevonden?

V: Hoe prioriteer ik herstelmaatregelen als er meerdere kwetsbaarheden zijn gevonden?nA: Geef prioriteit aan kwetsbaarheden op basis van de combinatie van exploitatiemogelijkheid en potentiële impact, waarbij kritieke bevindingen zoals kloonbare credentials op beveiligde deuren direct worden aangepakt. Minder urgente bevindingen, zoals kleine procedurele tekortkomingen, kunnen worden ingepland binnen reguliere changemanagementcycli, mits ze gedocumenteerd en gemonitord worden.

Related Articles