Executive brief
The Phison PS3111-S11 SSD controller firmware contains vendor unique commands (VUCs) accessible over the standard ATA interface with weak or absent authentication. An attacker with local access to an SSD can bypass the authentication mechanism to read and write the controller's memory and raw flash storage, potentially installing persistent firmware implants that survive power cycles and system reinstalls.
Technical details
This vulnerability involves the exposure of privileged vendor unique commands (VUCs) over the ATA interface due to absent or defeatable authentication mechanisms in Phison PS3111-S11 firmware. The authentication relies on a weak CRC-16 based unlock handshake that can be bypassed, or in some builds is absent entirely. An attacker with local administrative access can exploit this to directly read and write controller memory and raw flash, allowing arbitrary firmware modification, data exfiltration from hidden system areas, and installation of persistent implants. The attack vector is local requiring system access but no network connectivity. Patches addressing this issue have not been publicly confirmed available for all affected firmware versions.
Affected products
- Phison PS3111-S11 Controller Firmware through SBFQT1.3
Timeline
- 2026-09-02: published
- 2026-09-02: disclosed