HIGHVulnerability

CVE-2026-82876

Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can generate arbitrary RSA key pairs, sign modified firmware with the private key, embed the matching modulus in the signature segment, and the controller accepts the tampered firmware as valid.

Properties

severity
HIGH
score
8.2
epss_score
0.00087
cve_id
CVE-2026-82876
vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
published_at
2026-08-31T11:16:41.190
last_modified
2026-09-02T15:17:43.983
epss_percentile
0.00396

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Verification of Cryptographic Signature

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82876 — Ninja Signal Threat Intelligence | Ninja Signal