CVE-2026-82876
Received Received - Intake

Phison PS3111-S11 Firmware RSA Signature Spoofing

Vulnerability report for CVE-2026-82876, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulnCheck

Description

Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can generate arbitrary RSA key pairs, sign modified firmware with the private key, embed the matching modulus in the signature segment, and the controller accepts the tampered firmware as valid.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
phison ps3111-s11_firmware *
phison ps3111-s11_firmware to sbfqt1.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Phison PS3111-S11 controller firmware. The issue is that the firmware verifies RSA signatures using a public modulus embedded within the firmware image itself instead of using an immutable storage anchor. Attackers can generate arbitrary RSA key pairs, sign modified firmware with the private key, and embed the matching modulus in the signature segment. This allows the controller to accept tampered firmware as valid.

Detection Guidance

Detecting this vulnerability requires checking if your Phison PS3111-S11 controller firmware is vulnerable. Use tools like psychite from the GitHub repository to inspect firmware versions and verify signature verification mechanisms. Commands may include reading firmware details via /dev/sg0 (Linux) or \\.\PhysicalDrive0 (Windows) and comparing versions against SBFQT1.3.

Impact Analysis

Attackers could exploit this to install malicious firmware on devices using the Phison PS3111-S11 controller, potentially leading to data theft, unauthorized access, or system compromise. Since the controller accepts tampered firmware, it could allow persistent malware infections or bypass security controls on affected SSDs.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if it results in unauthorized data access or breaches. GDPR requires protection against unauthorized data processing, while HIPAA mandates secure handling of protected health information. Exploitation of this flaw may violate these regulations, leading to legal and financial penalties.

Mitigation Strategies

Immediately update the Phison PS3111-S11 controller firmware to the latest version beyond SBFQT1.3. Avoid using unofficial or modified firmware. If updates are unavailable, isolate affected systems to prevent potential exploitation. Monitor vendor advisories for patches.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82876. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart