Vulnerability handling policy
Published:2026-01-05
1. Vulnerability Disclosure Statement
As the manufacturer of our products, we pay great attention to the security of our products and services, and we highly value user privacy and data security. Collaborative efforts from all parties are an indispensable part of corporate security. If you discover or encounter potential security vulnerabilities while using our products, we encourage you to disclose your findings to us as soon as possible. Details will be handled in accordance with this Vulnerability Disclosure Policy. We guarantee that we have dedicated professionals responsible for following up, analyzing, and handling the issues you report, publishing them, and responding in a timely manner.
2. Vulnerability Feedback and Handling Process
2.1 Vulnerability Feedback
We prioritize the security experience of every user. If you encounter any potential security vulnerabilities or issues while using our products, we encourage you to report them to us immediately. Your active participation is a key factor in improving product security.
Feedback Steps:
- Describe the problem: Please describe the security issue or the vulnerability you have identified in detail, including the product model and the specific circumstances of occurrence.
- Collect information: If possible, please provide steps to reproduce the issue, the impact caused, and relevant screenshots or logs.
- Submit report: Please send an email to mailto:sales@szcecb.com to report the issue to our Product Security Team, or click on customer service to contact us.
2.2 Vulnerability Handling Process
- The reporter provides as much detailed information about the vulnerability as possible.
- Our company inspects, verifies, and evaluates the received vulnerability information.
- Fix the vulnerability and verify the product fix.
- Release a new version of the product for updates.
- Reply to the reporter with the handling results.
- Monitor product stability after the update.
2.3 Vulnerability Review Phase
- Feedback will be acknowledged within 3 business days of receipt, and a preliminary report will be submitted for evaluation.
- The evaluation will be completed within 7 business days.
- Once the vulnerability is confirmed, a remediation plan will be developed. The specific remediation timeline will be determined based on the vulnerability severity level.
2.4 Vulnerability Remediation and Completion Phase
- Critical vulnerabilities will be fixed within 3 business days after evaluation.
- High-risk vulnerabilities will be fixed within 7 business days after evaluation.
- Medium-risk vulnerabilities will be fixed within 30 business days after evaluation.
- Low-risk vulnerabilities will be fixed within 60 business days after evaluation.
The final remediation timeline will be determined based on actual circumstances. For vulnerabilities with severe or major impact, a separate emergency security advisory will be issued.
3. Vulnerability Rating Criteria
Based on the severity of the vulnerability, these are classified into four levels: Extreme Risk, High Risk, Medium Risk, and Low Risk. When we receive a vulnerability report, we take a series of measures to resolve it internally, referencing ISO/IEC 30111. All reported vulnerabilities are scored in accordance with the Common Vulnerability Scoring System (CVSS) 3.1 standard.
3.1 Critical Vulnerabilities
- Vulnerabilities allowing remote direct access to system privileges (server privileges, client privileges, smart devices), including but not limited to arbitrary code execution, arbitrary command execution, and upload/use of WebShell trojans.
- Logical design flaws in core business systems, including but not limited to arbitrary account password modification without any protection restrictions, arbitrary account login, etc.
- Severe vulnerabilities directly leading to core database leakage, including but not limited to SQL injection vulnerabilities.
- Server-side: Vulnerabilities allowing remote access to device execution privileges in an internet environment (e.g., downloading other privileges, user data, remote device access, etc.), and vulnerabilities allowing remote command execution bypassing authentication on the internet.
3.2 High-Risk Vulnerabilities
- Directly causing leakage of sensitive information on online servers, including but not limited to core system source code leakage, server sensitive log file downloads, etc.
- Vulnerabilities that allow impersonation to execute all functions, unauthorized access to important core business systems or sensitive functions, etc.
- Unauthorized access to management platforms and administrator functions, including but not limited to backend administrator accounts, related platform activities, user groups, important functions, and user-sensitive information.
- Including but not limited to vulnerabilities that can cause massive leakage of sensitive data, or lead to large-scale user identity information leakage.
- Device: Unauthorized acquisition of device execution privileges from a LAN (e.g., downloading other user data or remote device access). Interactive remote command execution vulnerabilities within a LAN.
- Server-side: Vulnerabilities causing permanent denial of service to devices, including but not limited to remote denial of service attacks on system devices (devices become unusable, permanently damaged, or the entire system needs to be rewritten).
3.3 Medium-Risk Vulnerabilities
- General information leakage, including but not limited to plaintext password storage, sensitive information contained in servers or databases, source code compressed package downloads, etc.
- Logical design flaws, defects existing in the system, such as defects in protection logic for temperature, overvoltage, etc.
- Vulnerabilities requiring interaction to obtain user identity information, including but not limited to sensitive operations such as CSRF, stored XSS, JSONP hijacking of sensitive information, etc.
- Denial of service vulnerabilities that may cause certain functions to be disabled.
- Allowing users to impersonate others to execute all functions, especially operations exceeding their privileges.
3.4 Low-Risk Vulnerabilities
- Vulnerabilities that can be exploited for phishing attacks, including but not limited to URL redirection vulnerabilities.
- Low-risk logical design flaws.
- Minor information leakage vulnerabilities, including but not limited to path disclosure, git file disclosure, and server-side business log content.
- Vulnerabilities that may be used for phishing or hacking attacks, including but not limited to arbitrary URL manipulation and reflected XSS vulnerabilities.
- Vulnerabilities causing temporary denial of service to devices, including but not limited to vulnerabilities resulting from temporary denial of service attacks.
3.5 Out-of-Scope Issues
- System bugs (non-security issues) unrelated to security, such as: slow network speed, page rendering errors, layout issues, etc.
- Reports that are too brief to reproduce the vulnerability, and reproduction remains impossible even after multiple communications.
- Harmless/non-exploitable vulnerabilities, prank CSRF, local DoS (not affecting others), Self-XSS, PDF XSS, non-sensitive information leakage (intranet IP/domain name), mail bombing, etc.
- Impractical source code leaks, source code is leaked but has no actual exploit value.
- Issues not related to our company's modules/hardware.
- Known/already disclosed vulnerabilities.
- Products no longer under maintenance.
- Vulnerabilities already known and fixed internally, verified by our company.
- Third-party component liability.
All product vulnerability information provided to our company, including all information in the product vulnerability report, shall be owned and used by our company.
Our company reserves the right to modify this policy at any time.
Related News
Contact Information
Service Hotline
Customer Service Email
Company Address
Room 1005, Building 30, Suzhou Nano City, 99 Jinji Lake Avenue, Suzhou City, Jiangsu Province
follow us
Powered by:www.300.cn | Hefei | Tag