top of page
perceptive_background_267k.jpg

Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable…

Published:

31 augustus 2026 om 00:00:00

Alert date:

31 augustus 2026 om 14:01:50

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Mobile & IoT, Zero-Day Vulnerabilities, Database & Storage

A critical vulnerability exists in the Phison PS3111-S11 storage controller firmware where RSA signature verification is fundamentally broken. The firmware validates signatures using a public modulus embedded within the firmware image itself rather than storing it in immutable, trusted hardware storage. This design flaw allows attackers to generate their own RSA key pairs, sign malicious firmware with the private key, and embed the corresponding public modulus into the firmware image. The controller then accepts this attacker-crafted firmware as legitimate, completely bypassing firmware integrity protections. This vulnerability enables persistent, low-level compromise of storage devices using the affected controller, potentially surviving OS reinstalls and standard security measures. The attack could be used to deploy firmware-level implants or destructive payloads on affected drives. Public proof-of-concept tooling and detailed writeups are available, significantly lowering the barrier to exploitation.

Technical details

Mitigation steps:

Affected products:

Phison PS3111-S11 controller firmware

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page