Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-02 01:17
Updated : 2026-09-10 15:47
NVD link : CVE-2026-84696
Mitre link : CVE-2026-84696
CVE.ORG link : CVE-2026-84696
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
