<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>PS3111-S11 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ps3111-s11/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 31 Aug 2026 12:00:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ps3111-s11/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper RSA Signature Validation in Phison PS3111-S11 Controller Firmware</title><link>https://feed.craftedsignal.io/briefs/2026-08-phison-firmware-vulnerability/</link><pubDate>Mon, 31 Aug 2026 12:00:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-phison-firmware-vulnerability/</guid><description>The Phison PS3111-S11 controller firmware is vulnerable to arbitrary firmware modification due to RSA signature validation against an embedded public modulus rather than immutable hardware-backed storage.</description><content:encoded><![CDATA[<p>The Phison PS3111-S11 controller firmware contains a critical architectural flaw (CVE-2026-82876) where RSA signature verification for firmware updates relies on a public modulus embedded directly within the mutable firmware image. Because this modulus is not anchored in immutable storage, such as a hardware-based root of trust, the verification process is entirely dependent on data that can be modified by an attacker. This flaw allows unauthorized parties to perform a man-in-the-middle or direct-access attack to replace legitimate firmware with malicious versions. By generating a custom RSA key pair and embedding the attacker-controlled public modulus into the signature segment of a tampered firmware image, the controller incorrectly identifies the malicious code as signed and legitimate. This vulnerability enables persistent, deep-level compromise of the storage device controller, potentially leading to unauthorized data access, persistence, and complete bypass of hardware-level security controls.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the installation of malicious, persistent firmware on the Phison PS3111-S11 controller. This provides an attacker with the ability to execute code at the controller level, potentially bypassing OS-level protections and maintaining long-term presence on the storage device that survives operating system reinstallation or disk formatting.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize inventory of devices utilizing the Phison PS3111-S11 controller to assess the exposure surface. Coordinate with hardware vendors to determine if firmware update mechanisms or patches are available to mitigate the reliance on mutable signature verification. As this vulnerability occurs at the controller level, traditional OS-level security logs may not be sufficient for detection; consider firmware integrity monitoring if supported by the management infrastructure.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>hardware-security</category><category>firmware-vulnerability</category><category>persistence</category></item></channel></rss>