Select another country or region to get content for your location.
Quick Links

    Vulnerability Handling Process

    MAXHUB's principles for vulnerability management

    MAXHUB has always regarded building and fully implementing an "end-to-end global cybersecurity assurance system" as one of its important development strategies. It has established a sustainable and reliable vulnerability management system from the aspects of policy, organization, process, management, technology and standards, and works with external stakeholders in an open manner to jointly address the challenges of vulnerabilities.

    To clarify MAXHUB 's basic stance and position on vulnerabilities, MAXHUB proposes five fundamental principles for vulnerability management:

    1. Reduce harm and lower risk

    Reducing or eliminating the harm caused to customers by vulnerabilities in MAXHUB products and services, and mitigating the potential security risks posed by vulnerabilities to customers/users, is both our vision for vulnerability management and the value guideline we follow in vulnerability handling and disclosure.

    2. Reduce and eliminate vulnerabilities

    Although it is generally agreed in the industry that vulnerabilities are unavoidable, we will still strive to: 1) take measures to reduce vulnerabilities in our products and services; 2) provide customers/users with risk mitigation solutions in a timely manner once vulnerabilities in our products and services are discovered.

    Throughout the vulnerability handling process, MAXHUB PSIRT strictly controls the scope of vulnerability information, disseminating it only among personnel involved in handling vulnerabilities; it also requests that the person reporting the vulnerability keep the information confidential until our clients have obtained a complete solution.

    3. Proactive Management

    Vulnerability issues require collaborative efforts from upstream and downstream partners in the supply chain to resolve. We will proactively identify our responsibilities in vulnerability management and clarify jurisdictional boundaries, including applicable regulatory requirements, contractual requirements, and applicable public standards for business operations, and build a management system for proactive management.

    4. Continuous optimization

    Cybersecurity is a dynamic and evolving process, and as threats evolve, defenders also need to continuously innovate. We will continue to optimize our vulnerability management workflows and standards, constantly learn from industry standards and best practices, and improve our maturity in vulnerability management.

    5. Open Collaboration

    We will uphold an open and collaborative attitude, strengthen connections between the supply chain and the external security ecosystem, including upstream and downstream of the supply chain, security researchers, security companies, and security regulatory agencies; and enhance collaboration with stakeholders in vulnerability-related work to build trustworthy cooperative relationships.

    Based on the above principles and in accordance with industry standard ISO 27001 , MAXHUB has established a comprehensive vulnerability management process. MAXHUB is committed to a responsible attitude and strives to protect its customers to the greatest extent possible, minimizing the risk of vulnerabilities being exploited.

    Vulnerability Handling Process

    MAXHUB is committed to enhancing product security and fully supporting the secure operation of its customers' networks and businesses. MAXHUB prioritizes vulnerability management in product development and maintenance, and has established a complete vulnerability handling process in accordance with standards such as ISO/IEC 27001 to improve product security and ensure timely response when vulnerabilities are discovered.

    placeholder

    1. Vulnerability awareness: Accepting and collecting suspected vulnerabilities in products;

    2. Verification & Assessment: Confirm the validity and scope of impact of suspected vulnerabilities;

    3. Vulnerability patching: Develop and implement vulnerability patching plans;

    4. Vulnerability patch information release: Releasing vulnerability patch information to customers;

    5. Closed-loop improvement: Continuous improvement based on customer feedback and practical experience.

    Detecting vulnerabilities promptly is a crucial prerequisite for timely response. On one hand, MAXHUB encourages security researchers, industry organizations, customers, and suppliers to proactively report vulnerabilities to MAXHUB. PSIRT reports suspected vulnerabilities and compels upstream suppliers to promptly report vulnerabilities in deliverables to MAXHUB . Conversely, MAXHUB proactively monitors well-known public vulnerability databases, open-source communities, and security websites to promptly identify vulnerabilities related to MAXHUB products. MAXHUB manages identified suspected vulnerabilities and verifies the impact on all non-EOS (End of Service & Support) product versions. Based on industry best practices, MAXHUB strongly recommends that customers regularly review whether their products are still supported to ensure they receive the latest software updates.

    For any reports submitted to MAXHUB suspected vulnerabilities identified by PSIRT, PSIRT will work with the product team to analyze/verify the vulnerabilities, assess their severity based on their actual impact on the product, determine patching priorities, and develop remediation solutions (including mitigation measures, patches/versions, and other risk reduction measures that customers can implement). MAXHUB , based on the principles of minimizing harm and reducing risk, will release vulnerability information to stakeholders to support customers in assessing the actual risk of vulnerabilities to their networks.

    MAXHUB discovers vulnerabilities in a supplier's products or services during product development, delivery, or deployment, it will proactively communicate patching requests to the supplier. For open-source software vulnerabilities, MAXHUB will adhere to the vulnerability management policies of the open-source community, submitting suspected vulnerabilities to the community to encourage timely release of patches, and actively contributing patching solutions to the open-source community.

    MAXHUB PSIRT will coordinate with the vulnerability reporter to handle the issue, acting as a coordinator or through a third-party coordination center to report the vulnerability to other vendors, standards organizations, etc., and promote its resolution. If the vulnerability involves standards protocols, it is recommended that the reporter submit it to MAXHUB. While submitting PSIRT, industry organizations are also notified simultaneously.

    Based on the principle of continuous optimization, MAXHUB will continue to improve its products in terms of security and vulnerability handling processes.

    Throughout the vulnerability handling process, MAXHUB PSIRT strictly controls the scope of vulnerability information, disseminating it only among personnel involved in handling vulnerabilities; it also requests that the person reporting the vulnerability keep the information confidential until our clients have obtained a complete solution.

    MAXHUB will take necessary and reasonable protective measures for the data it acquires in accordance with legal compliance requirements. MAXHUB will not proactively share or disclose the aforementioned data to any other party unless explicitly requested by affected customers or required by law.

    Vulnerability Severity Assessment

    MAXHUB employs industry-standard criteria to assess the severity of suspected vulnerabilities in its products. Taking CVSS (Common Vulnerability Scoring System) as an example, this model comprises three groups of metrics: basic metrics, time-based metrics, and environment-based metrics. MAXHUB provides a basic vulnerability score, and in some cases, a time-based vulnerability score and an environment-based vulnerability score under typical scenarios. MAXHUB encourages end-users to evaluate the environment-based vulnerability score based on their actual network conditions. This evaluation serves as the final vulnerability score for the vulnerability in the user's specific environment, supporting the user's decision-making regarding vulnerability mitigation deployment.

    Because different industries follow different standards, MAXHUB uses Security Severity Rating (SSR) as a simpler classification method. SSR classifies vulnerabilities based on a comprehensive score of vulnerability severity assessment, dividing vulnerabilities into five levels: Critical, High, Medium, Low, and Informational.

    Third-party software vulnerabilities

    Due to the diverse ways and scenarios in which MAXHUB products integrate third-party software/components, MAXHUB will adjust the vulnerability scores for third-party software/components according to the specific scenarios of the product to reflect the true impact of the vulnerabilities. For example, if the affected module of a certain third-party software/component is not called, the vulnerability is considered "unexploitable and unaffected." If the existing assessment system cannot cover the assessment dimensions, MAXHUB is responsible for interpreting the assessment results.

    If all three of the following criteria are met, MAXHUB will designate this vulnerability as "High Profile":
    • A CVSS score of 6.0 or higher is required.
    • This vulnerability has attracted widespread public attention.
    • This vulnerability is likely to have an exploit available, or may be being actively exploited.

    For third-party vulnerabilities classified as "High profile," MAXHUB will review all non-EOS product versions and, upon confirmation of a "High profile" vulnerability, will issue a security notification within 24 hours to inform relevant customers of MAXHUB 's status regarding the vulnerability's handling. Once a patch is available, MAXHUB will provide risk decision-making and mitigation support to affected customers through security bulletins. For third-party vulnerabilities not classified as "High profile," MAXHUB will provide details in the version/patch documentation.

    Release vulnerability information announcement

    Announcement format

    MAXHUB releases vulnerability information and patch solutions to the public in the following three ways:

    Security Advisory (SA): A security advisory contains information such as vulnerability severity level, business impact, and remediation plans to communicate vulnerability mitigation solutions. Security advisories (SA) are used to publish information on critical and high-level vulnerabilities directly related to MAXHUB products, along with their remediation plans. Security advisories (SA) provide an option to download the Common Vulnerability Reporting Framework (CVRF) content, designed to describe vulnerability information in a machine-readable format (XML file) to support the use of tools by affected customers.

    Security Notices (SNs) are responses to publicly discussed security topics related to the product (including both vulnerability-related and non-vulnerability-related topics). SNs are used to publish information related to vulnerabilities assessed as Informational or Low-level by SSR, such as information discussed in public forums (blogs or discussion lists). SNs are also used in specific scenarios where they may attract widespread public attention to vulnerabilities in MAXHUB product versions, or where MAXHUB has observed active exploitation of vulnerabilities, to inform relevant customers of MAXHUB 's progress in responding to these vulnerabilities.

    Release Note (RN): The Release Note contains information on patched vulnerabilities. It is part of the accompanying deliverables for product releases and describes vulnerabilities assessed as Medium by Security Severity Rating (SSR). To facilitate customers' comprehensive assessment of vulnerability risks from a release/patch perspective, the Release Note (RN) also includes vulnerability information and remediation plans published through Security Announcements (SAs). For private cloud scenarios, MAXHUB includes this information in the release documentation of its cloud service products. For endpoint scenarios, MAXHUB includes it in its routine patch announcements.

    Announcement Plan

    MAXHUB will issue an SN or SA to provide customers with live network risk decision support when one or more of the following conditions are met .

    • Security Severity Rating (SSR) is defined as a vulnerability that is "Critical" or "High". MAXHUB completes the vulnerability response process and can provide vulnerability patching solutions to support customers in mitigating risks in their live networks.
    • A vulnerability in a MAXHUB product version may attract widespread public attention or if MAXHUB has observed active exploitation of the vulnerability, which may increase the risks faced by MAXHUB customers, MAXHUB will expedite the response process and notify customers within 24 hours of confirming that the above conditions are met, and will continue to update them on the progress of the vulnerability response.
    • To minimize global cyber risks, MAXHUB follows a collaborative vulnerability disclosure (CVD) strategy to determine its disclosure plan when coordinating disclosures with third parties.

    Announcement Schedule

    To better support customers in developing deployment patch plans and conducting risk assessments, MAXHUB will release SAs based on actual product conditions . However, MAXHUB may also release SAs outside of the planned release schedule. The following situations (not an exhaustive list) may lead to unplanned SA releases:

    • MAXHUB has observed active exploitation of the vulnerability.
    • MAXHUB has noticed widespread public concern about vulnerabilities in its products.
    • MAXHUB collaborated with third parties to disclose the vulnerability.

    Instructions for obtaining software updates

    Vulnerability management is based on product/software version lifecycle milestones. MAXHUB PSIRT will manage vulnerabilities in all product versions prior to the end of service and support (EOS). Vulnerability patches will be provided before EOFS (End of Full Support), and after EOFS, critical or high-level vulnerabilities in SSR will be patched as appropriate. Product teams may define milestones outside of this policy; for such vulnerability patching, please refer to the specific product documentation for details on available remediation support.

    Customers can upgrade to newer product/software versions or install the latest patches to mitigate vulnerability risks, according to their contracts. Customers can only obtain and use software versions with valid purchased licenses (currently activated licenses). Patching vulnerabilities in the product/version does not grant customers the right to obtain new software licenses, other software features/functions, or major version upgrades. Customers can contact MAXHUB service engineers or after-sales support to obtain versions/patches.

    MAXHUB enterprise customers should refer to the Enterprise Business Product Lifecycle Termination Policy and download here. Understand the details of vulnerability patching throughout the product lifecycle.

    Disclaimer & Reserved Rights

    If this document is available in multiple languages, and there are any discrepancies between the different language versions, the Chinese version shall prevail. The strategy descriptions in this document do not constitute a guarantee or commitment, nor do they form part of any contract. MAXHUB may adjust the above strategies as appropriate.

    MAXHUB reserves the right to change or update this document at any time. We will update this policy statement as necessary to increase transparency or respond more proactively, for example:

    • Feedback from customers, regulators, industry, or other stakeholders.
    • Changes in overall strategy.
    • The introduction of best practices, etc.

    When we publish changes to this policy statement, we will revise the "Update Date" at the bottom of this policy.

    Definition

    The following definition is used in this strategy:

    name definition
    PGP Pretty Good Privacy Policy is a hybrid encryption system combining asymmetric and symmetric encryption, which is mainly used to encrypt emails and files, and can also be used for digital signature.
    ISO/IEC 27001 Information security management system developed by the International Organization for Standardization
    CVSS Common Vulnerability Scoring System
    SSR Security Severity Rating
    EOFS End of Full Support. Fixes for newly discovered bugs will cease, and no new patch versions will be released. Existing bugs will continue to be analyzed and fixed.
    EOS End of Service & Support: Service and support will cease. No further technical support, including troubleshooting and fixing new issues, will be provided.

    Updated on July 15, 2026.

    This site uses cookies to personalise your experience and analyse site traffic. By clicking ACCEPT or continuing to browse the site, you are agreeing to our use of cookies. See our Cookies and Privacy Policy here

    {$ title $}
    {$ description $}

    {$ text $}

    {$ title $}
    pic