Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-84696: Phison PS3111‑S11 controller firmware lets attackers alter memory

CVE-2026-84696 · published 27 days ago
Summary

The firmware used in Phison PS3111‑S11 storage controllers can be tricked into accepting special commands without proper authentication. This allows a malicious user to read from and write to the controller's internal memory and flash storage, letting them install hidden code that survives a restart. Update the firmware to a version that fixes the command authentication or replace the device if a safe update is not available.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
phison electronics corporation ps3111-s11 controller firmware SBFQT1.3
Original advisory text
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can by...
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.
Severity
9.3 Critical
CVSS 3.1: 8.2 (MITRE)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published2 Sep 2026
Updated27 Sep 2026
First seen2 Sep 2026
Sources
CVE-2026-84696 · MITRE
Track software like this
Free during beta