Firmware Signature Verification Bypass in Phison PS3111-S11 Controller
CVE-2026-82876
Key Information:
- Vendor
- CVE Published:
- 31 August 2026
Badges
What is CVE-2026-82876?
The Phison PS3111-S11 controller firmware exhibits a critical flaw in its RSA signature verification process. The firmware improperly validates RSA signatures using a public modulus that is hardcoded within the firmware image, instead of employing securely stored immutable references. This design flaw allows attackers to generate arbitrary RSA key pairs, create maliciously modified firmware signed with the corresponding private key, and embed the embedded public modulus into the signature segment. Consequently, the firmware will accept this altered version as authentic, granting unauthorized control over the firmware execution and possibly leading to further exploits.
Affected Version(s)
PS3111-S11 Controller Firmware SBFQT1.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
