Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Michael Herbert

#17464of 56,333
16.4Total CVSS
Vulnerabilities · 2
High
2
PT-2026-84575
8.2
2026-09-02
Phison · Ps3111-S11 · CVE-2026-84696
**Name of the Vulnerable Software and Affected Versions** Phison PS3111-S11 controller firmware versions through SBFQT1.3 **Description** Privileged vendor unique commands are exposed over the ATA interface due to absent or defeatable authentication mechanisms. This allows attackers to bypass the weak CRC-16 based unlock handshake or exploit builds that lack a VUC lock to read and write controller memory and raw flash, enabling the persistence of implants across power cycles. **Recommendations** Update Phison PS3111-S11 controller firmware to a version later than SBFQT1.3.
PT-2026-83780
8.2
2026-08-31
Phison · Ps3111-S11 · CVE-2026-82876
**Name of the Vulnerable Software and Affected Versions** Phison PS3111-S11 controller firmware (affected versions not specified) **Description** The firmware verifies RSA signatures using a public modulus embedded within the firmware image instead of using one anchored in immutable storage. This allows an attacker to generate arbitrary RSA key pairs, sign modified firmware with the private key, and embed the corresponding modulus in the signature segment, leading the controller to accept the tampered firmware as valid. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.