CVE-2026-84696: Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands

Published Sep 2, 2026
·
Updated

Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.

Affected Software

1 affected component
Phison PS3111-S11 controller firmware<=SBFQT1.3

Event History

Sep 2, 2026
CVE Published
via MITRE·12:37 AM
Data Sourced
via MITRE·12:37 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can realistically exploit this issue?

An attacker needs local access to the affected drive through its ATA interface and high privileges, as reflected by the PR:H vector. The issue is most relevant where a privileged local user, administrator, or actor with direct host or drive access can issue vendor-specific ATA commands.

2

What capabilities does successful exploitation provide?

An attacker can read and write controller memory and raw flash through privileged vendor unique commands. This can enable implants that persist across power cycles and can affect confidentiality, integrity, and availability.

3

Are all affected firmware builds protected by an unlock mechanism?

No. Some builds have no vendor unique command lock, while others use a weak CRC-16-based unlock handshake that can be bypassed.

4

Which firmware versions are affected?

Phison PS3111-S11 controller firmware versions through SBFQT1.3 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203