Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-82876: Phison PS3111‑S11 controller can run malicious firmware
CVE-2026-82876 · published 29 days ago
Summary
The PS3111‑S11 controller's firmware checks its own signatures using a public key that is stored inside the firmware itself instead of a permanent, protected location. Because this key can be altered, an attacker could create a fake firmware update that appears authentic and cause the controller to load malicious code. Apply any firmware updates provided by Phison and ensure only trusted, digitally signed firmware is installed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| phison electronics corporation | ps3111-s11 controller firmware | SBFQT1.3 |
Original advisory text
Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can generate arbi...
Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can generate arbitrary RSA key pairs, sign modified firmware with the private key, embed the matching modulus in the signature segment, and the controller accepts the tampered firmware as valid.
Severity
9.3
Critical
CVSS 3.1: 8.2 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published31 Aug 2026
Updated25 Sep 2026
First seen31 Aug 2026
Track software like this
Free during beta