Product Security

Product Security

> 日本語

Vulnerability Disclosure Policy and Advisories

To better protect our customers and their data, OPTOELECTRONICS CO.,LTD. welcomes reports of potential security vulnerabilities in our products and services from customers, security researchers, academic institutions and other members of the security community.

This policy applies to all products, services and digital assets that we develop, maintain or operate. Third-party products and services that we neither develop nor control fall outside its scope.

Reporting a vulnerability

If you have found a vulnerability, please send the following information to .

Every report is reviewed by our internal product security team, which attempts to reproduce the issue on the affected product. We aim to acknowledge receipt within 5 business days and to provide the results of our initial assessment within 10 business days.

1. Product identification
Model name, serial number, software or firmware version.

2. Nature of the vulnerability
The technical class of the flaw, for example buffer overflow or improper input validation.

3. Proof of concept
Clear and detailed steps, log files or a working script that allow the issue to be reproduced safely.

4. Evidence of exploitation
Please state explicitly if you have observed the vulnerability being exploited, or hold reliable evidence that it has been.

5. Contact detailsoptional
Used to keep you informed of our progress and to follow up on questions.

6. Your nameoptional
If you would like to be credited in the advisory, please tell us whether we may name you and how you wish to be identified.

Reports may be submitted anonymously. We assess every report on the technical merits of its content.

Actively exploited vulnerabilities

Vulnerabilities that are already being exploited are handled with priority and outside the timeframes above. Please begin the subject line with [URGENT] and state this clearly at the top of your message.

Please note:

• By contacting us at this address, you are deemed to have agreed to our Privacy Policy.

• This address accepts vulnerability reports concerning our products only. We are unable to respond to other enquiries.

• If your report contains material that requires particular care, such as exploit code, please contact us first without that material. We will then arrange a secure channel for the follow-up exchange.

• We may ask you for further information, such as details of your operating environment, and would appreciate your cooperation.

• We may be unable to assess a report if the information provided is incomplete.

• As a precaution against spoofed email, we verify the safety of incoming messages before acting on them. This may delay our reply, and we may withhold a reply to messages we judge to be suspicious. We appreciate your understanding.

• We do not currently operate a bug bounty programme.

Related security information

To support information sharing on security matters, we may also publish articles on the following subjects.

• Newly introduced security features

• Product-specific security configuration guides and best practices

• Vulnerabilities in third-party components identified by vulnerability scanning tools
Limited to those that are not exploitable from within the affected product.

• Installation instructions for specific security updates

• The effect of security updates to products from other manufacturers on the coexistence requirements and prerequisites of our products

Disclosure

Where we identify a vulnerability in our own products, a CVE ID is assigned where appropriate and the vulnerability is listed in the table below.

To protect users, technical details are withheld until a reliable fix has been validated and is ready for release.

Once the fix has been released, we publish a security advisory setting out the nature of the vulnerability, its impact and the affected versions.

We recommend that customers check this page regularly so that security updates can be applied in good time.

Verifying the files we publish

To confirm that a file published by OPTOELECTRONICS CO.,LTD. is authentic and has not been altered, verify its detached signature (.sig file) using the public PGP key below. Detached signatures are provided alongside each security advisory and firmware download.

This key is used for signing only and cannot be used to encrypt messages.

User IDOPTO PSIRT <>
Key ID22157FD10F0D7C85
Fingerprint4645 EF35 7A7F EF93 ED4F  8BF4 2215 7FD1 0F0D 7C85
Type / ExpiresRSA 4096 bit / 8 September 2027
DownloadPublic key file (.asc)
Authoritative copy, hosted on our website.
keys.openpgp.org
The same key, for cross-checking against the fingerprint above.

Security advisories

Published Details
- -

No security advisories have been published at this time.

お問い合わせ

CONTACT

各種お問い合わせは、こちらより承ります。お気軽にお問い合わせください。

お問い合わせ

ホームページからのお問い合わせ

お問い合わせ一覧へ