Vulnerability Reporting and Handling Policy

Feasycom follows the Coordinated Vulnerability Disclosure (CVD) principle.

01 / Vulnerability Information Disclosure

Feasycom follows the Coordinated Vulnerability Disclosure (CVD) principle. On the premise that vulnerabilities are properly resolved and risks are minimized, we provide users with sufficient information to assess risks to their systems. Security advisories will be published at an appropriate time, disclosing information about verified vulnerabilities and remediation guidance. For details, please refer to our Security Advisories page.

CVD principle
Coordinated Vulnerability Disclosure

On the premise that vulnerabilities are properly resolved and risks are minimized.

02 / Reporting Vulnerabilities to the Feasycom PSIRT

2.1 / Kontaktinformationen

If you discover a potential security vulnerability in Feasycom products, please contact us through the following channel:

psirt@feasycom.com

2.2 / PGP/GPG Encrypted Submission

When the report involves sensitive information such as vulnerability exploitation details or proof-of-concept (PoC) code, we recommend encrypting it with the Feasycom PSIRT PGP/GPG public key before sending it to psirt@feasycom.com.

Public key fingerprint

50A9 E1B6 97C7 BFF7 7ABC 6FF8 D471 B433 0886 956F

Please follow the steps below to import the public key and send encrypted files:

01

Download and import the public key

Download the public key file and import it by double-clicking the file (Gpg4win for Windows, GPG Suite for macOS). Download the public key file

02

Verify the fingerprint

Double-click the public key file (.asc) downloaded from this page. Once the key has been imported, verify that its fingerprint matches the one displayed above.

03

Sign and encrypt

Right-click the target file and select “Sign and Encrypt”. Then send the resulting .gpg file to the designated email address.

03 / Reporting Content Guidelines

To help the Feasycom PSIRT handle potential vulnerabilities, please provide the following information:

Product information:product name, version number, or revision number
Vulnerability description:a detailed description of the vulnerability
Exploitation method:details on potential exploitation of the vulnerability
Date of discovery:the date the vulnerability was detected
Discovery method:details on how the vulnerability was discovered
Verification method:how the potential vulnerability was verified
Technische Details:system configuration, trace files, exploit/attack code descriptions, sample packet captures, usw.
Related software:names and versions of software used for verification (if applicable)
Supplementary materials:any other items used for verification (if applicable)
Public information:any published public information (CVE IDs, academic papers, usw.)
CVSS score:if possible, please provide a Common Vulnerability Scoring System (CVSS) v3 score
Contact information:your name, organization/department name, email address, and phone number

Insufficient information may make it impossible to verify the report.

04 / Report Handling Process

The Feasycom PSIRT follows the process below to handle each vulnerability report:

  1. 01Vulnerability intake
  2. 02Analysis and verification
  3. 03Solution development
  4. 04Disclosure and remediation

Vulnerability intake: upon receiving a security vulnerability report, the PSIRT team performs an initial confirmation.

Analysis and verification: verify the authenticity of the vulnerability, analyze the scope of impact, and assess the risk level.

Solution development: after confirming the impact of the vulnerability, work with the product team to develop a remediation plan (including mitigations and solutions).

Disclosure and remediation: maintain communication with the reporter, assist in fixing the vulnerability, and complete the coordinated disclosure of the vulnerability.

Feasycom is committed to keeping sensitive information related to the vulnerability confidential to the reporter until the vulnerability is fixed and the security advisory is published.

05 / Response Time Commitments

The Feasycom PSIRT commits to the following target timeframes for every valid vulnerability report:

  1. 1. Acknowledgment:

    acknowledge receipt within 7 business days of receiving the report and provide a unique tracking number for the reporter to check the handling progress;

  2. 2. Assessment and severity rating:

    complete the technical assessment and severity rating within 15 business days of confirmation (critical vulnerabilities are expedited on a priority basis);

  3. 3. Interim mitigation measures:

    provide actionable interim mitigation recommendations within 10 business days of completing the assessment;

  4. 4. Fix verification:

    the target timeframe is no more than 30 days for critical vulnerabilities and no more than 60 days for high-severity vulnerabilities; medium- and low-severity vulnerabilities are fixed with subsequent product version iterations;

  5. 5. Disclosure cycle:

    security advisories are published in principle within 90 days of confirmation (the industry-common disclosure cycle); if an extension is necessary, we will negotiate with the reporter and synchronize the remediation progress.

The above timeframes are response targets. Actual progress may be affected by the product lifecycle, third-party component dependencies, and verification complexity. The PSIRT will keep the reporter updated on progress throughout the process.

06 / Safe Harbor Statement and Out-of-Scope Items

Safe Harbor Statement

Feasycom commits: no legal action or administrative complaint will be taken against security researchers who conduct security research in good faith and responsibly, and who submit vulnerability reports in accordance with this policy; the identity of the reporter and the content of communications will be kept strictly confidential until the vulnerability is fixed and the security advisory is published. We also kindly request that reporters allow a reasonable time for remediation before public disclosure and keep verification activities to the minimum necessary to avoid affecting real user data.

Out-of-Scope Items

The following items fall outside the scope of PSIRT acceptance and remediation:

  1. Vulnerabilities in third-party components (chip vendor SDKs, open-source software, usw.): we recommend reporting directly to the upstream vendor; we can assist in forwarding and coordinated handling;
  2. Products that have exceeded their support period (EOL): no fixes or security advisories will be provided; upgrading to a supported version is recommended;
  3. Social engineering attacks, phishing, and physical-access attacks;
  4. Denial-of-service issues that do not affect data security or service availability;
  5. Purely theoretical issues for which no exploitability evidence can be provided;
  6. Issues related to demo environments and test sites.

Reports on the above out-of-scope items are not guaranteed remediation or disclosure, but will still receive a reply.

Jetzt chatten