ZeroHour

CVE-2026-82876

mass

Firmware signature verification bypass in Phison PS3111-S11 SSD controllers

CVSS 4.0
9.3 critical
EPSS
<1%p0
Published
()
Modified
AI analysis

Phison PS3111-S11 SSD controller firmware validates RSA firmware signatures against a public modulus embedded in the firmware image itself, rather than one anchored in immutable storage such as ROM or one-time-programmable memory, so the root of trust is not fixed. An attacker with the ability to write firmware to the drive can generate their own RSA key pair, sign modified firmware with the private key, and embed the matching modulus in the signature segment; the controller then accepts the tampered firmware as authentic. This completely defeats firmware authentication, allowing persistent, stealthy malicious firmware with high impact on the confidentiality, integrity, and availability of data on the drive (CVSS 4.0 rates it 9.3 Critical, with local attack vector and high privileges required). Any system using an SSD built on a PS3111-S11 controller is affected; these controllers shipped in high volumes inside consumer and OEM SATA drives sold under many brands. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists; EPSS currently estimates a 0.1% probability of exploitation within 30 days.

What to do: Identify whether your SSDs use a PS3111-S11 controller (e.g., via CrystalDiskInfo or the drive vendor's utility) and apply firmware updates from the SSD vendor or Phison when released, since remediation requires reflashing the controller rather than a host-side patch. Until then, only run firmware-update utilities and firmware images obtained from trusted vendor sources, and treat local administrator compromise as sufficient for an attacker to install tampered drive firmware. No workaround is available because the flawed key-verification design resides in the controller firmware itself.

Affected
Phison PS3111-S11 SSD controller firmware
Estimated exposure
masspotentially millions of SSDs (PS3111-S11 controllers shipped in large volumes of consumer SATA drives across many brands) — Estimated from deployment patterns: Phison's S11 controller family was one of the most widely deployed consumer SATA SSD controllers, used in popular drives from numerous OEM brands, so the installed base is plausibly in the millions,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can generate arbitrary RSA key pairs, sign modified firmware with the private key, embed the matching modulus in the signature segment, and the controller accepts the tampered firmware as valid.

Weakness
CWE-347
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.