Select another country or region to get content for your location.
Quick Links

    Vulnerability Reporting

    Report suspected vulnerabilities

    If you encounter or discover any suspected vulnerabilities in MAXHUB products, please inform MAXHUB promptly. For PSIRT, please refer to the vulnerability reporting channels and security mechanisms to submit suspected vulnerabilities.

    Vulnerability reporting channels

    You can submit suspected vulnerabilities related to MAXHUB products via email using the template provided . PSIRT will verify any suspected vulnerabilities reported by security researchers, industry organizations, customers, and suppliers as soon as possible.

    Channel Note
    Email address: security@maxhub.com MAXHUB within 24 hours . PSIRT confirmed the issue via email and will keep you informed of the progress of the problem as it unfolds.
    Telephone: +86-020-82086168 9:00-18:00 (GMT+8)

    Security Mechanism

    Encrypt any messages sent to security@maxhub.com using PGP (Pretty Good Privacy) . Our PGP public key (key ID 0x50A34966; PGP fingerprint: 5930 0A75 BD8C 54CA 6471 B25A 998D D4C6 50A3 4966 ) can be obtained by clicking here .

    Throughout the vulnerability handling process, MAXHUB PSIRT strictly controls the scope of vulnerability information, disseminating it only among personnel involved in handling vulnerabilities; it also requests that the person reporting the vulnerability keep the information confidential until our clients have obtained a complete solution.

    Response range

    MAXHUB PSIRT focuses on receiving all vulnerabilities related to MAXHUB products. For issues with MAXHUB products (such as product configuration, patch acquisition, and live vulnerability remediation support), you can directly contact MAXHUB after-sales support for relevant technical support. MAXHUB will handle vulnerabilities identified by after-sales support during the technical support process according to its internal procedures .

    Communication Commitment

    We commit to providing feedback and tracking the progress of your vulnerability reports according to the following steps.

    Node Commitment Time Limit
    Confirm receipt of report and assign tracking number 3 business days
    Preliminary verification results feedback (valid/invalid/requires supplementation) 10 business days
    Processing progress update At least once every 30 days until closed.
    Fixes, releases, and announcements 10 business days after the vulnerability is patched

    Coordination over oversights and the embargo period

    1. The default coordination and disclosure period is 90 days from the date of verification and confirmation;
    2. Please do not disclose vulnerability details before a fix is available and an announcement is released . We also promise to fix the vulnerability promptly and explain it in the announcement ;
    3. After the patch is released, we will publish the patched vulnerability information in accordance with the "Security Bulletin" ;

    Acknowledgments and Recognition

    With your consent, we will acknowledge you in the security bulletin or on the acknowledgments page.

    Expectations for the Reporter's Behavior

    To protect user privacy, data security, and service stability, please ensure that reporters adhere to the following boundaries when verifying vulnerabilities:

    1. Only test to the minimum necessary extent to verify vulnerabilities, and avoid unnecessary in-depth probing;
    2. Do not damage, tamper with, delete, download, or disclose any sensitive or business data that does not belong to you;
    3. Do not engage in destructive behaviors such as DoS/DDoS attacks, social engineering, physical attacks, malicious persistence, ransomware, or lateral movement;
    4. Do not conduct any tests that may affect the stability of the production environment and service availability;
    5. Do not disclose sensitive details to third parties before the vulnerability has been patched .

    Policy Maintenance

    This policy is maintained by the Information Security Department and reviewed at least once a year.

    This site uses cookies to personalise your experience and analyse site traffic. By clicking ACCEPT or continuing to browse the site, you are agreeing to our use of cookies. See our Cookies and Privacy Policy here

    {$ title $}
    {$ description $}

    {$ text $}

    {$ title $}
    pic