← volver
CVE-2026-82876criticalCWE-347

Phison PS3111-S11 Controller Firmware Signature Verification Bypass

48Vexday Risk Score

Sin señal de explotación. Ella tiene prueba de concepto pública.

ssvc Attendcvss 9.3epss 0.1%
de la publicación al arma4 días
Publicada en NVD31 ago
1ª PoC+4d
probabilidad de explotación
0.1%top 100% de las CVE
explotación observada
noninguna fuente lo reporta
2 exploit(s) público(s)
Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can generate arbitrary RSA key pairs, sign modified firmware with the private key, embed the matching modulus in the signature segment, and the controller accepts the tampered firmware as valid.
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.