{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aphisonps3111_s11/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:phison:ps3111_s11:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-82876"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PS3111-S11"],"_cs_severities":["high"],"_cs_tags":["hardware-security","firmware-vulnerability","persistence"],"_cs_type":"advisory","_cs_vendors":["Phison"],"content_html":"\u003cp\u003eThe Phison PS3111-S11 controller firmware contains a critical architectural flaw (CVE-2026-82876) where RSA signature verification for firmware updates relies on a public modulus embedded directly within the mutable firmware image. Because this modulus is not anchored in immutable storage, such as a hardware-based root of trust, the verification process is entirely dependent on data that can be modified by an attacker. This flaw allows unauthorized parties to perform a man-in-the-middle or direct-access attack to replace legitimate firmware with malicious versions. By generating a custom RSA key pair and embedding the attacker-controlled public modulus into the signature segment of a tampered firmware image, the controller incorrectly identifies the malicious code as signed and legitimate. This vulnerability enables persistent, deep-level compromise of the storage device controller, potentially leading to unauthorized data access, persistence, and complete bypass of hardware-level security controls.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the installation of malicious, persistent firmware on the Phison PS3111-S11 controller. This provides an attacker with the ability to execute code at the controller level, potentially bypassing OS-level protections and maintaining long-term presence on the storage device that survives operating system reinstallation or disk formatting.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize inventory of devices utilizing the Phison PS3111-S11 controller to assess the exposure surface. Coordinate with hardware vendors to determine if firmware update mechanisms or patches are available to mitigate the reliance on mutable signature verification. As this vulnerability occurs at the controller level, traditional OS-level security logs may not be sufficient for detection; consider firmware integrity monitoring if supported by the management infrastructure.\u003c/p\u003e\n","date_modified":"2026-08-31T12:00:38Z","date_published":"2026-08-31T12:00:38Z","id":"https://feed.craftedsignal.io/briefs/2026-08-phison-firmware-vulnerability/","summary":"The Phison PS3111-S11 controller firmware is vulnerable to arbitrary firmware modification due to RSA signature validation against an embedded public modulus rather than immutable hardware-backed storage.","title":"Improper RSA Signature Validation in Phison PS3111-S11 Controller Firmware","url":"https://feed.craftedsignal.io/briefs/2026-08-phison-firmware-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:phison:ps3111_s11:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}