CVE-2026-84696: Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.
Affected Software
Event History
Frequently Asked Questions
Who can realistically exploit this issue?
An attacker needs local access to the affected drive through its ATA interface and high privileges, as reflected by the PR:H vector. The issue is most relevant where a privileged local user, administrator, or actor with direct host or drive access can issue vendor-specific ATA commands.
What capabilities does successful exploitation provide?
An attacker can read and write controller memory and raw flash through privileged vendor unique commands. This can enable implants that persist across power cycles and can affect confidentiality, integrity, and availability.
Are all affected firmware builds protected by an unlock mechanism?
No. Some builds have no vendor unique command lock, while others use a weak CRC-16-based unlock handshake that can be bypassed.
Which firmware versions are affected?
Phison PS3111-S11 controller firmware versions through SBFQT1.3 are affected.