---
id: CVE-2026-82876
title: >-
  Phison PS3111-S11 controller firmware verifies RSA signatures using a public
  modulus embedded within the firmware image itself rather than anchored in
  immutable storage
summary: >-
  Phison PS3111-S11 controller firmware verifies RSA signatures using a public
  modulus embedded within the firmware image itself rather than anchored in
  immutable storage. Attackers can generate arbitrary RSA key pairs, sign
  modified firmw…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-347
vendor: Phison Electronics Corporation
product: PS3111-S11 Controller Firmware
affected:
  - ps3111-s11_controller_firmware SBFQT1.3
published: '2026-08-31'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:47:22.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82876'
references:
  - url: 'https://github.com/trulycrisp/psychite'
    label: disclosure@vulncheck.com
  - url: 'https://trulycrisp.github.io/drivefirmware/phison_s11/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/phison-ps3111-s11-controller-firmware-signature-verification-bypass
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-02T14:57:14.123777Z'
ingestedAt: '2026-09-14T13:32:51.317Z'
epss: 0.00121
epssPercentile: 0.01672
exploits:
  github: 1
  githubRepos:
    - >-
      https://github.com/Hunt-Benito/the-key-ships-with-the-lock-cve-2026-82876-phison-s11-ssd-firmware-signature-bypass
  checkedAt: '2026-09-26T09:06:02.248Z'
---

## Overview

Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can generate arbitrary RSA key pairs, sign modified firmware with the private key, embed the matching modulus in the signature segment, and the controller accepts the tampered firmware as valid.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
